XSS Vulnerability in DrayTek Vigor2925 Router
CVE-2019-16533

6.1MEDIUM

Key Information:

Vendor
Draytek
Vendor
CVE Published:
20 September 2019

Summary

A Cross-Site Scripting (XSS) vulnerability has been identified in the loginset.htm file of DrayTek Vigor2925 routers running firmware version 3.8.4.3. This flaw permits incorrect access control, allowing attackers to execute scripts in the context of the user's session. It's important to note that DrayTek Vigor2925 is an end-of-life product, which increases the risk of exploitation. Users should consider upgrading to a supported device to mitigate security risks.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.