First published: Tue Mar 06 2018(Updated: )
Cross-site scripting (XSS) vulnerability in DrayTek Vigor AP910C devices with firmware 1.2.0_RC3 build r6594 allows remote attackers to inject arbitrary web script or HTML via vectors involving home.asp.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Draytek Vigorap 910c Firmware | =1.2.0-rc3 | |
Draytek Vigorap 910c |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2017-11650.
CVE-2017-11650 has a severity rating of 6.1 (medium).
The affected software for CVE-2017-11650 is DrayTek Vigor AP910C devices with firmware 1.2.0_RC3 build r6594.
CVE-2017-11650 allows remote attackers to inject arbitrary web script or HTML via vectors involving home.asp.
Yes, updating the firmware to a version that addresses the vulnerability is the recommended fix for CVE-2017-11650.