DrayTek Vigor3910 devices through 4.3.2.6 have a stack-based overflow when processing query string parameters because GetCGI mishandles extraneous ampersand characters and long key-value pairs.
https://thehackernews.com/2024/12/cisa-and-fbi-raise-alerts-on-exploited.html
https://www.forescout.com/resources/draytek14-vulnerabilities
https://www.forescout.com/resources/draybreak-draytek-research/