Vigor3910 Devices Vulnerable to Reflected XSS
CVE-2024-41584

Currently unrated

Key Information:

Vendor

DrayTek

Vendor
CVE Published:
3 October 2024

What is CVE-2024-41584?

DrayTek Vigor3910 devices through 4.3.2.6 are vulnerable to reflected XSS by authenticated users, caused by missing validation of the sFormAuthStr parameter.

References

Timeline

  • Vulnerability published

.
CVE-2024-41584 : Vigor3910 Devices Vulnerable to Reflected XSS