Cyber Posture

CVE-2024-41334

High

Published: 27 February 2025

Published
27 February 2025
Modified
03 June 2025
KEV Added
Patch
CVSS Score 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.0014 33.0th percentile
Risk Priority 18 60% EPSS · 20% KEV · 20% CVSS

Summary

CVE-2024-41334 is a high-severity Improper Certificate Validation (CWE-295) vulnerability in Draytek Vigor166 Firmware. Its CVSS base score is 8.8 (High).

Operationally, ranked at the 33.0th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

The strongest mitigations our analysis identified are NIST 800-53 CM-14 (Signed Components) and SR-11 (Component Authenticity).

Threat & Defense at a Glance

What defenders deploy: see the NIST 800-53 controls recommended below.
Threat & Defense Details

Mitigating Controls (NIST 800-53 r5)AI

prevent

Requires digital signature verification of software and firmware components prior to installation, directly preventing upload of crafted APPE modules lacking valid certificates from unauthorized servers.

prevent

Mandates verification of component authenticity before installation or execution, blocking exploitation via unauthenticated APPE modules from non-official sources.

preventdetect

Employs integrity verification mechanisms for software and firmware to prevent and detect unauthorized modifications, such as those from improperly validated APPE modules.

NVD Description

Draytek devices Vigor 165/166 prior to v4.2.6 , Vigor 2620/LTE200 prior to v3.9.8.8, Vigor 2860/2925 prior to v3.9.7, Vigor 2862/2926 prior to v3.9.9.4, Vigor 2133/2762/2832 prior to v3.9.8, Vigor 2135/2765/2766 prior to v4.4.5.1, Vigor 2865/2866/2927 prior to v4.4.5.3, Vigor 2962/3910…

more

prior to v4.3.2.7, Vigor 3912 prior to v4.3.5.2, and Vigor 2925 up to v3.9.6 were discovered to not utilize certificate verification, allowing attackers to upload crafted APPE modules from non-official servers, leading to arbitrary code execution.

Deeper analysisAI

CVE-2024-41334 is an improper certificate validation vulnerability (CWE-295) affecting multiple Draytek Vigor router models, including Vigor 165/166 prior to v4.2.6, Vigor 2620/LTE200 prior to v3.9.8.8, Vigor 2860/2925 prior to v3.9.7, Vigor 2862/2926 prior to v3.9.9.4, Vigor 2133/2762/2832 prior to v3.9.8, Vigor 2135/2765/2766 prior to v4.4.5.1, Vigor 2865/2866/2927 prior to v4.4.5.3, Vigor 2962/3910 prior to v4.3.2.7, Vigor 3912 prior to v4.3.5.2, and Vigor 2925 up to v3.9.6. The flaw occurs because these devices do not perform certificate verification when uploading APPE (Application Program Extension Environment) modules, enabling the installation of modules from unauthorized sources.

Attackers can exploit this vulnerability over the network with low complexity and low privileges (PR:L), requiring no user interaction. Successful exploitation allows uploading crafted APPE modules from non-official servers, resulting in arbitrary code execution on the device. The CVSS v3.1 base score of 8.8 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) reflects high impacts on confidentiality, integrity, and availability.

Mitigation involves updating affected devices to the vendor-recommended firmware versions listed above, as indicated in the vulnerability description. Additional details are available in advisories from Draytek at http://draytek.com and Faraday Labs at https://medium.com/faraday/advisory-multiple-vulnerabilities-affecting-draytek-routers-78a6cb8b3946.

Details

CWE(s)

Affected Products

draytek
vigor166 firmware
≤ 4.2.6
draytek
vigor2620 firmware
≤ 3.9.8.8
draytek
vigorlte200 firmware
≤ 3.9.8.8
draytek
vigor2860 firmware
≤ 3.9.7
draytek
vigor2925 firmware
≤ 3.9.7
draytek
vigor2862 firmware
≤ 3.9.9.4
draytek
vigor2926 firmware
≤ 3.9.9.4
draytek
vigor2133 firmware
≤ 3.9.8
draytek
vigor2762 firmware
≤ 3.9.8
draytek
vigor2832 firmware
≤ 3.9.8
+10 more product configuration(s) — see NVD for full list

CVEs Like This One

CVE-2024-41340Same product: Draytek Vigor165
CVE-2024-41338Same product: Draytek Vigor165
CVE-2024-41339Same product: Draytek Vigor165
CVE-2024-51139Same product: Draytek Vigor2133
CVE-2024-51138Same product: Draytek Vigor2133
CVE-2026-3040Same vendor: Draytek
CVE-2024-54848Shared CWE-295
CVE-2025-1193Shared CWE-295
CVE-2026-34580Shared CWE-295
CVE-2025-46788Shared CWE-295

References