XSS Vulnerability in DrayTek Vigor2925 Router
CVE-2019-16533
6.1MEDIUM
Summary
A Cross-Site Scripting (XSS) vulnerability has been identified in the loginset.htm file of DrayTek Vigor2925 routers running firmware version 3.8.4.3. This flaw permits incorrect access control, allowing attackers to execute scripts in the context of the user's session. It's important to note that DrayTek Vigor2925 is an end-of-life product, which increases the risk of exploitation. Users should consider upgrading to a supported device to mitigate security risks.
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved