CVE-2025-10547CRITICAL 9.8EPSS p42.2%

CVE-2025-10547CVE-2025-10547

Description

An uninitialized variable in the HTTP CGI request arguments processing component of Vigor Routers running DrayOS may allow an attacker the ability to perform RCE on the appliance through memory corruption.

Scoring

CVSS 3.19.8 (CRITICAL)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS0.56% probability of exploitation · percentile 42.2% · 2026-06-21T12:00:28Z
Published2025-10-03
Last modified2026-04-15

References

  1. https://www.draytek.com/about/security-advisory/use-of-uninitialized-variable-vulnerabilities/
  2. https://www.kb.cert.org/vuls/id/294418

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
Multiple DrayTek Vigor Routers Web Management Page Vulnerability
CVE
DrayTek Vigor Routers OS Command Injection Vulnerability
CVE
DrayTek Multiple Vigor Routers OS Command Injection Vulnerability
CVE
CVE-2026-1457
CVE
CVE-2025-13547
CVE
CVE-2025-41426
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.