First published: Fri Sep 20 2019(Updated: )
On DrayTek Vigor2925 devices with firmware 3.8.4.3, XSS exists via a crafted WAN name on the General Setup screen. NOTE: this is an end-of-life product.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Draytek Vigor2925 Firmware | =3.8.4.3 | |
Draytek Vigor 2925 | ||
Draytek Vigor 2925n | ||
Draytek Vigor2925ac | ||
Draytek Vigor2925fn | ||
Draytek Vigor2925n-plus | ||
Draytek Vigor2925vac | ||
Draytek Vigor2925vn-plus |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-16534 is a vulnerability that exists on DrayTek Vigor2925 devices with firmware 3.8.4.3, allowing XSS attacks via a crafted WAN name on the General Setup screen.
CVE-2019-16534 has a severity rating of 6.1 (Medium).
DrayTek Vigor2925 devices with firmware version 3.8.4.3 are affected by CVE-2019-16534.
To address CVE-2019-16534, it is recommended to update the firmware on the affected DrayTek Vigor2925 devices.
More information about CVE-2019-16534 can be found on the DrayTek website and Facebook post provided in the references.