CVE-2019-16533
20.09.2019, 16:15
On DrayTek Vigor2925 devices with firmware 3.8.4.3, Incorrect Access Control exists in loginset.htm, and can be used to trigger XSS. NOTE: this is an end-of-life product.
Vendor | Product | Version |
---|---|---|
draytek | vigor2925_firmware | 3.8.4.3 |
𝑥
= Vulnerable software versions
References