Vulnerabilities > Draytek > Vigor2962 Firmware > High

DATE CVE VULNERABILITY TITLE RISK
2024-10-03 CVE-2024-41594 Inadequate Encryption Strength vulnerability in Draytek products
An issue in DrayTek Vigor310 devices through 4.3.2.6 allows an attacker to obtain sensitive information because the httpd server of the Vigor management UI uses a static string for seeding the PRNG of OpenSSL.
network
low complexity
draytek CWE-326
7.5