Vigor3910 Devices Vulnerable to Reflected XSS
CVE-2024-41584
Currently unrated
Summary
DrayTek Vigor3910 devices through 4.3.2.6 are vulnerable to reflected XSS by authenticated users, caused by missing validation of the sFormAuthStr parameter.
References
Timeline
Vulnerability published