CVE-2023-23313
03.03.2023, 22:15
Certain Draytek products are vulnerable to Cross Site Scripting (XSS) via the wlogin.cgi script and user_login.cgi script of the router's web application management portal. This affects Vigor3910, Vigor1000B, Vigor2962 v4.3.2.1; Vigor2865 and Vigor2866 v4.4.1.0; Vigor2927 v4.4.2.2; and Vigor2915, Vigor2765, Vigor2766, Vigor2135 v4.4.2.0; Vigor2763 v4.4.2.1; Vigor2862 and Vigor2926 v3.9.9.0; Vigor2925 v3.9.3; Vigor2952 and Vigor3220 v3.9.7.3; Vigor2133 and Vigor2762 v3.9.6.4; and Vigor2832 v3.9.6.2.
Vendor | Product | Version |
---|---|---|
draytek | vigor2860_firmware | 𝑥 < 3.9.4 |
draytek | vigor2860n_firmware | 𝑥 < 3.9.4 |
draytek | vigor2860n-plus_firmware | 𝑥 < 3.9.4 |
draytek | vigor2860vn-plus_firmware | 𝑥 < 3.9.4 |
draytek | vigor2860ac_firmware | 𝑥 < 3.9.4 |
draytek | vigor2860vac_firmware | 𝑥 < 3.9.4 |
draytek | vigor2860l_firmware | 𝑥 < 3.9.4 |
draytek | vigor2860ln_firmware | 𝑥 < 3.9.4 |
draytek | vigor2832_firmware | 𝑥 < 3.9.6.3 |
draytek | vigor2832n_firmware | 𝑥 < 3.9.6.3 |
draytek | vigor2766_firmware | 𝑥 < 4.4.2.1 |
draytek | vigor2766ax_firmware | 𝑥 < 4.4.2.1 |
draytek | vigor2766ac_firmware | 𝑥 < 4.4.2.1 |
draytek | vigor2766vac_firmware | 𝑥 < 4.4.2.1 |
draytek | vigor2765_firmware | 𝑥 < 4.4.2.1 |
draytek | vigor2765ax_firmware | 𝑥 < 4.4.2.1 |
draytek | vigor2765ac_firmware | 𝑥 < 4.4.2.1 |
draytek | vigor2765va_firmware | 𝑥 < 4.4.2.1 |
draytek | vigor2763_firmware | 𝑥 < 4.4.2.2 |
draytek | vigor2763ac_firmware | 𝑥 < 4.4.2.2 |
draytek | vigor2762_firmware | 𝑥 < 3.9.6.5 |
draytek | vigor2762n_firmware | 𝑥 < 3.9.6.5 |
draytek | vigor2762ac_firmware | 𝑥 < 3.9.6.5 |
draytek | vigor2762vac_firmware | 𝑥 < 3.9.6.5 |
draytek | vigor2135_firmware | 𝑥 < 4.4.2.1 |
draytek | vigor2135ax_firmware | 𝑥 < 4.4.2.1 |
draytek | vigor2135ac_firmware | 𝑥 < 4.4.2.1 |
draytek | vigor2135vac_firmware | 𝑥 < 4.4.2.1 |
draytek | vigor2135fvac_firmware | 𝑥 < 4.4.2.1 |
draytek | vigor2133_firmware | 𝑥 < 3.9.6.5 |
draytek | vigor2133n_firmware | 𝑥 < 3.9.6.5 |
draytek | vigor2133ac_firmware | 𝑥 < 3.9.6.5 |
draytek | vigor2133vac_firmware | 𝑥 < 3.9.6.5 |
draytek | vigor2133fvac_firmware | 𝑥 < 3.9.6.5 |
draytek | vigor166_firmware | 𝑥 < 4.2.4.1 |
draytek | vigor165_firmware | 𝑥 < 4.2.4.1 |
draytek | vigor130_firmware | 𝑥 < 3.8.5.1 |
draytek | vigornic_132_firmware | 𝑥 < 3.8.5.1 |
draytek | vigor3910_firmware | 𝑥 < 4.3.2.2 |
draytek | vigor3220_firmware | 𝑥 < 3.9.7.4 |
draytek | vigor2962_firmware | 𝑥 < 4.3.2.2 |
draytek | vigor2962p_firmware | 𝑥 < 4.3.2.2 |
draytek | vigor1000b_firmware | 𝑥 < 4.3.2.2 |
draytek | vigor2952_firmware | 𝑥 < 3.9.7.4 |
draytek | vigor2952p_firmware | 𝑥 < 3.9.7.4 |
draytek | vigor2927_firmware | 𝑥 < 4.4.2.3 |
draytek | vigor2927ax_firmware | 𝑥 < 4.4.2.3 |
draytek | vigor2927ac_firmware | 𝑥 < 4.4.2.3 |
draytek | vigor2927vac_firmware | 𝑥 < 4.4.2.3 |
draytek | vigor2927f_firmware | 𝑥 < 4.4.2.3 |
draytek | vigor2927l_firmware | 𝑥 < 4.4.2.3 |
draytek | vigor2927lac_firmware | 𝑥 < 4.4.2.3 |
draytek | vigor2926_firmware | 𝑥 < 3.9.9.1 |
draytek | vigor2926n_firmware | 𝑥 < 3.9.9.1 |
draytek | vigor2926ac_firmware | 𝑥 < 3.9.9.1 |
draytek | vigor2926vac_firmware | 𝑥 < 3.9.9.1 |
draytek | vigor2926l_firmware | 𝑥 < 3.9.9.1 |
draytek | vigor2926ln_firmware | 𝑥 < 3.9.9.1 |
draytek | vigor2926lac_firmware | 𝑥 < 3.9.9.1 |
draytek | vigor2925_firmware | 𝑥 < 3.9.4 |
draytek | vigor2925n_firmware | 𝑥 < 3.9.4 |
draytek | vigor2925n-plus_firmware | 𝑥 < 3.9.4 |
draytek | vigor2925vn-plus_firmware | 𝑥 < 3.9.4 |
draytek | vigor2925ac_firmware | 𝑥 < 3.9.4 |
draytek | vigor2925vac_firmware | 𝑥 < 3.9.4 |
draytek | vigor2925fn_firmware | 𝑥 < 3.9.4 |
draytek | vigor2925l_firmware | 𝑥 < 3.9.4 |
draytek | vigor2925ln_firmware | 𝑥 < 3.9.4 |
draytek | vigor2915_firmware | 𝑥 < 4.4.2.1 |
draytek | vigor2915ac_firmware | 𝑥 < 4.4.2.1 |
draytek | vigor2866_firmware | 𝑥 < 4.4.1.1 |
draytek | vigor2866ax_firmware | 𝑥 < 4.4.1.1 |
draytek | vigor2866ac_firmware | 𝑥 < 4.4.1.1 |
draytek | vigor2866vac_firmware | 𝑥 < 4.4.1.1 |
draytek | vigor2866l_firmware | 𝑥 < 4.4.1.1 |
draytek | vigor2866lac_firmware | 𝑥 < 4.4.1.1 |
draytek | vigor2865_firmware | 𝑥 < 4.4.1.1 |
draytek | vigor2865ax_firmware | 𝑥 < 4.4.1.1 |
draytek | vigor2865ac_firmware | 𝑥 < 4.4.1.1 |
draytek | vigor2865vac_firmware | 𝑥 < 4.4.1.1 |
draytek | vigor2865l_firmware | 𝑥 < 4.4.1.1 |
draytek | vigor2865lac_firmware | 𝑥 < 4.4.1.1 |
draytek | vigor2862_firmware | 𝑥 < 3.9.9.1 |
draytek | vigor2862n_firmware | 𝑥 < 3.9.9.1 |
draytek | vigor2862ac_firmware | 𝑥 < 3.9.9.1 |
draytek | vigor2862vac_firmware | 𝑥 < 3.9.9.1 |
draytek | vigor2862b_firmware | 𝑥 < 3.9.9.1 |
draytek | vigor2862bn_firmware | 𝑥 < 3.9.9.1 |
draytek | vigor2862l_firmware | 𝑥 < 3.9.9.1 |
draytek | vigor2862ln_firmware | 𝑥 < 3.9.9.1 |
draytek | vigor2862lac_firmware | 𝑥 < 3.9.9.1 |
𝑥
= Vulnerable software versions