CVE-2019-16533: XSS
Published Sep 20, 2019
·Updated
On DrayTek Vigor2925 devices with firmware 3.8.4.3, Incorrect Access Control exists in loginset.htm, and can be used to trigger XSS. NOTE: this is an end-of-life product.
Affected Software
8 affected components
DrayTek Vigor2925 Firmware=3.8.4.3
DrayTek Vigor 2925
DrayTek Vigor 2925n
DrayTek Vigor2925ac
DrayTek Vigor2925fn
DrayTek Vigor2925n-plus
DrayTek Vigor2925vac
DrayTek Vigor2925vn-plus
Event History
Sep 20, 2019
CVE Published
via MITRE·03:22 PM
Data Sourced
via MITRE·03:22 PM
Description
Frequently Asked Questions
1
What is CVE-2019-16533?
CVE-2019-16533 is a vulnerability that exists in loginset.htm on DrayTek Vigor2925 devices with firmware 3.8.4.3, allowing for XSS attacks.
2
What is the severity of CVE-2019-16533?
The severity of CVE-2019-16533 is medium with a CVSS score of 6.1.
3
How can CVE-2019-16533 be exploited?
CVE-2019-16533 can be exploited by triggering XSS attacks through loginset.htm on affected DrayTek Vigor2925 devices with firmware 3.8.4.3.
4
Is DrayTek Vigor 2925 affected by CVE-2019-16533?
No, DrayTek Vigor 2925 devices are not affected by CVE-2019-16533.
5
How can I fix CVE-2019-16533?
To fix CVE-2019-16533, users should update their DrayTek Vigor2925 devices to a firmware version that addresses the vulnerability.