CVE-2019-16534: XSS
Published Sep 20, 2019
·Updated
On DrayTek Vigor2925 devices with firmware 3.8.4.3, XSS exists via a crafted WAN name on the General Setup screen. NOTE: this is an end-of-life product.
Affected Software
8 affected components
DrayTek Vigor2925 Firmware=3.8.4.3
DrayTek Vigor 2925
DrayTek Vigor 2925n
DrayTek Vigor2925ac
DrayTek Vigor2925fn
DrayTek Vigor2925n-plus
DrayTek Vigor2925vac
DrayTek Vigor2925vn-plus
Event History
Sep 20, 2019
CVE Published
via MITRE·03:23 PM
Data Sourced
via MITRE·03:23 PM
Description
Frequently Asked Questions
1
What is CVE-2019-16534?
CVE-2019-16534 is a vulnerability that exists on DrayTek Vigor2925 devices with firmware 3.8.4.3, allowing XSS attacks via a crafted WAN name on the General Setup screen.
2
How severe is CVE-2019-16534?
CVE-2019-16534 has a severity rating of 6.1 (Medium).
3
Which DrayTek devices are affected by CVE-2019-16534?
DrayTek Vigor2925 devices with firmware version 3.8.4.3 are affected by CVE-2019-16534.
4
How can I fix CVE-2019-16534?
To address CVE-2019-16534, it is recommended to update the firmware on the affected DrayTek Vigor2925 devices.
5
Where can I find more information about CVE-2019-16534?
More information about CVE-2019-16534 can be found on the DrayTek website and Facebook post provided in the references.