CVE-2023-23313

Certain Draytek products are vulnerable to Cross Site Scripting (XSS) via the wlogin.cgi script and user_login.cgi script of the router's web application management portal. This affects Vigor3910, Vigor1000B, Vigor2962 v4.3.2.1; Vigor2865 and Vigor2866 v4.4.1.0; Vigor2927 v4.4.2.2; and Vigor2915, Vigor2765, Vigor2766, Vigor2135 v4.4.2.0; Vigor2763 v4.4.2.1; Vigor2862 and Vigor2926 v3.9.9.0; Vigor2925 v3.9.3; Vigor2952 and Vigor3220 v3.9.7.3; Vigor2133 and Vigor2762 v3.9.6.4; and Vigor2832 v3.9.6.2.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.1 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
mitreCNA
---
---
CVEADP
---
---
CISA-ADPADP
6.1 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 37%
VendorProductVersion
draytekvigor2860_firmware
𝑥
< 3.9.4
draytekvigor2860n_firmware
𝑥
< 3.9.4
draytekvigor2860n-plus_firmware
𝑥
< 3.9.4
draytekvigor2860vn-plus_firmware
𝑥
< 3.9.4
draytekvigor2860ac_firmware
𝑥
< 3.9.4
draytekvigor2860vac_firmware
𝑥
< 3.9.4
draytekvigor2860l_firmware
𝑥
< 3.9.4
draytekvigor2860ln_firmware
𝑥
< 3.9.4
draytekvigor2832_firmware
𝑥
< 3.9.6.3
draytekvigor2832n_firmware
𝑥
< 3.9.6.3
draytekvigor2766_firmware
𝑥
< 4.4.2.1
draytekvigor2766ax_firmware
𝑥
< 4.4.2.1
draytekvigor2766ac_firmware
𝑥
< 4.4.2.1
draytekvigor2766vac_firmware
𝑥
< 4.4.2.1
draytekvigor2765_firmware
𝑥
< 4.4.2.1
draytekvigor2765ax_firmware
𝑥
< 4.4.2.1
draytekvigor2765ac_firmware
𝑥
< 4.4.2.1
draytekvigor2765va_firmware
𝑥
< 4.4.2.1
draytekvigor2763_firmware
𝑥
< 4.4.2.2
draytekvigor2763ac_firmware
𝑥
< 4.4.2.2
draytekvigor2762_firmware
𝑥
< 3.9.6.5
draytekvigor2762n_firmware
𝑥
< 3.9.6.5
draytekvigor2762ac_firmware
𝑥
< 3.9.6.5
draytekvigor2762vac_firmware
𝑥
< 3.9.6.5
draytekvigor2135_firmware
𝑥
< 4.4.2.1
draytekvigor2135ax_firmware
𝑥
< 4.4.2.1
draytekvigor2135ac_firmware
𝑥
< 4.4.2.1
draytekvigor2135vac_firmware
𝑥
< 4.4.2.1
draytekvigor2135fvac_firmware
𝑥
< 4.4.2.1
draytekvigor2133_firmware
𝑥
< 3.9.6.5
draytekvigor2133n_firmware
𝑥
< 3.9.6.5
draytekvigor2133ac_firmware
𝑥
< 3.9.6.5
draytekvigor2133vac_firmware
𝑥
< 3.9.6.5
draytekvigor2133fvac_firmware
𝑥
< 3.9.6.5
draytekvigor166_firmware
𝑥
< 4.2.4.1
draytekvigor165_firmware
𝑥
< 4.2.4.1
draytekvigor130_firmware
𝑥
< 3.8.5.1
draytekvigornic_132_firmware
𝑥
< 3.8.5.1
draytekvirgor3910_firmware
𝑥
< 4.3.2.2
draytekvirgor3220_firmware
𝑥
< 3.9.7.4
draytekvirgor2962_firmware
𝑥
< 4.3.2.2
draytekvirgor2962p_firmware
𝑥
< 4.3.2.2
draytekvirgor1000b_firmware
𝑥
< 4.3.2.2
draytekvirgor2952_firmware
𝑥
< 3.9.7.4
draytekvirgor2952p_firmware
𝑥
< 3.9.7.4
draytekvirgor2927_firmware
𝑥
< 4.4.2.3
draytekvirgor2927ax_firmware
𝑥
< 4.4.2.3
draytekvirgor2927ac_firmware
𝑥
< 4.4.2.3
draytekvirgor2927vac_firmware
𝑥
< 4.4.2.3
draytekvirgor2927f_firmware
𝑥
< 4.4.2.3
draytekvirgor2927l_firmware
𝑥
< 4.4.2.3
draytekvirgor2927lac_firmware
𝑥
< 4.4.2.3
draytekvirgor2926_firmware
𝑥
< 3.9.9.1
draytekvirgor2926n_firmware
𝑥
< 3.9.9.1
draytekvirgor2926ac_firmware
𝑥
< 3.9.9.1
draytekvirgor2926vac_firmware
𝑥
< 3.9.9.1
draytekvirgor2926l_firmware
𝑥
< 3.9.9.1
draytekvirgor2926ln_firmware
𝑥
< 3.9.9.1
draytekvirgor2926lac_firmware
𝑥
< 3.9.9.1
draytekvirgor2925_firmware
𝑥
< 3.9.4
draytekvirgor2925n_firmware
𝑥
< 3.9.4
draytekvirgor2925n-plus_firmware
𝑥
< 3.9.4
draytekvirgor2925vn-plus_firmware
𝑥
< 3.9.4
draytekvirgor2925ac_firmware
𝑥
< 3.9.4
draytekvirgor2925vac_firmware
𝑥
< 3.9.4
draytekvirgor2925fn_firmware
𝑥
< 3.9.4
draytekvirgor2925l_firmware
𝑥
< 3.9.4
draytekvirgor2925ln_firmware
𝑥
< 3.9.4
draytekvirgor2915_firmware
𝑥
< 4.4.2.1
draytekvirgor2915ac_firmware
𝑥
< 4.4.2.1
draytekvirgor2866_firmware
𝑥
< 4.4.1.1
draytekvirgor2866ax_firmware
𝑥
< 4.4.1.1
draytekvirgor2866ac_firmware
𝑥
< 4.4.1.1
draytekvirgor2866vac_firmware
𝑥
< 4.4.1.1
draytekvirgor2866l_firmware
𝑥
< 4.4.1.1
draytekvirgor2866lac_firmware
𝑥
< 4.4.1.1
draytekvirgor2865_firmware
𝑥
< 4.4.1.1
draytekvirgor2865ax_firmware
𝑥
< 4.4.1.1
draytekvirgor2865ac_firmware
𝑥
< 4.4.1.1
draytekvirgor2865vac_firmware
𝑥
< 4.4.1.1
draytekvirgor2865l_firmware
𝑥
< 4.4.1.1
draytekvirgor2865lac_firmware
𝑥
< 4.4.1.1
draytekvirgor2862_firmware
𝑥
< 3.9.9.1
draytekvirgor2862n_firmware
𝑥
< 3.9.9.1
draytekvirgor2862ac_firmware
𝑥
< 3.9.9.1
draytekvirgor2862vac_firmware
𝑥
< 3.9.9.1
draytekvirgor2862b_firmware
𝑥
< 3.9.9.1
draytekvirgor2862bn_firmware
𝑥
< 3.9.9.1
draytekvirgor2862l_firmware
𝑥
< 3.9.9.1
draytekvirgor2862ln_firmware
𝑥
< 3.9.9.1
draytekvirgor2862lac_firmware
𝑥
< 3.9.9.1
𝑥
= Vulnerable software versions