← All CVEs

CVE-2025-10547

critical · 9.8

An uninitialized variable in the HTTP CGI request arguments processing component of Vigor Routers running DrayOS may allow an attacker the ability to perform RCE on the appliance through memory corruption.

9.8
CVSS
0.6%
EPSS (exploit prob.)
46th
EPSS percentile
2025-10-03
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2025-10547