An uninitialized variable in the HTTP CGI request arguments processing component of Vigor Routers running DrayOS may allow an attacker the ability to perform RCE on the appliance through memory corruption.
Metrics
Affected Vendors & Products
References
History
Mon, 06 Oct 2025 14:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Draytek
Draytek drayos Draytek vigor1000b Draytek vigor2135 Draytek vigor2763 Draytek vigor2765 Draytek vigor2766 Draytek vigor2862 Draytek vigor2865 Draytek vigor Routers |
|
Vendors & Products |
Draytek
Draytek drayos Draytek vigor1000b Draytek vigor2135 Draytek vigor2763 Draytek vigor2765 Draytek vigor2766 Draytek vigor2862 Draytek vigor2865 Draytek vigor Routers |
Fri, 03 Oct 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
Fri, 03 Oct 2025 11:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An uninitialized variable in the HTTP CGI request arguments processing component of Vigor Routers running DrayOS may allow an attacker the ability to perform RCE on the appliance through memory corruption. | |
Title | CVE-2025-10547 | |
References |
|

Status: PUBLISHED
Assigner: certcc
Published: 2025-10-03T11:35:43.752Z
Updated: 2025-10-03T14:34:32.239Z
Reserved: 2025-09-16T11:35:24.694Z
Link: CVE-2025-10547

Updated: 2025-10-03T14:33:10.714Z

Status : Awaiting Analysis
Published: 2025-10-03T12:15:42.993
Modified: 2025-10-06T14:56:47.823
Link: CVE-2025-10547

No data.