First published: Fri Sep 20 2019(Updated: )
On DrayTek Vigor2925 devices with firmware 3.8.4.3, Incorrect Access Control exists in loginset.htm, and can be used to trigger XSS. NOTE: this is an end-of-life product.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Draytek Vigor2925 Firmware | =3.8.4.3 | |
Draytek Vigor 2925 | ||
Draytek Vigor 2925n | ||
Draytek Vigor2925ac | ||
Draytek Vigor2925fn | ||
Draytek Vigor2925n-plus | ||
Draytek Vigor2925vac | ||
Draytek Vigor2925vn-plus |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-16533 is a vulnerability that exists in loginset.htm on DrayTek Vigor2925 devices with firmware 3.8.4.3, allowing for XSS attacks.
The severity of CVE-2019-16533 is medium with a CVSS score of 6.1.
CVE-2019-16533 can be exploited by triggering XSS attacks through loginset.htm on affected DrayTek Vigor2925 devices with firmware 3.8.4.3.
No, DrayTek Vigor 2925 devices are not affected by CVE-2019-16533.
To fix CVE-2019-16533, users should update their DrayTek Vigor2925 devices to a firmware version that addresses the vulnerability.