6.1

CVE-2023-23313

Certain Draytek products are vulnerable to Cross Site Scripting (XSS) via the wlogin.cgi script and user_login.cgi script of the router's web application management portal. This affects Vigor3910, Vigor1000B, Vigor2962 v4.3.2.1; Vigor2865 and Vigor2866 v4.4.1.0; Vigor2927 v4.4.2.2; and Vigor2915, Vigor2765, Vigor2766, Vigor2135 v4.4.2.0; Vigor2763 v4.4.2.1; Vigor2862 and Vigor2926 v3.9.9.0; Vigor2925 v3.9.3; Vigor2952 and Vigor3220 v3.9.7.3; Vigor2133 and Vigor2762 v3.9.6.4; and Vigor2832 v3.9.6.2.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
DraytekVigor2860 Firmware Version < 3.9.4
   DraytekVigor2860 Version-
DraytekVigor2860n Firmware Version < 3.9.4
   DraytekVigor2860n Version-
DraytekVigor2860n-plus Firmware Version < 3.9.4
   DraytekVigor2860n-plus Version-
DraytekVigor2860vn-plus Firmware Version < 3.9.4
   DraytekVigor2860vn-plus Version-
DraytekVigor2860ac Firmware Version < 3.9.4
   DraytekVigor2860ac Version-
DraytekVigor2860vac Firmware Version < 3.9.4
   DraytekVigor2860vac Version-
DraytekVigor2860l Firmware Version < 3.9.4
   DraytekVigor2860l Version-
DraytekVigor2860ln Firmware Version < 3.9.4
   DraytekVigor2860ln Version-
DraytekVigor2832 Firmware Version < 3.9.6.3
   DraytekVigor2832 Version-
DraytekVigor2832n Firmware Version < 3.9.6.3
   DraytekVigor2832n Version-
DraytekVigor2766 Firmware Version < 4.4.2.1
   DraytekVigor2766 Version-
DraytekVigor2766ax Firmware Version < 4.4.2.1
   DraytekVigor2766ax Version-
DraytekVigor2766ac Firmware Version < 4.4.2.1
   DraytekVigor2766ac Version-
DraytekVigor2766vac Firmware Version < 4.4.2.1
   DraytekVigor2766vac Version-
DraytekVigor2765 Firmware Version < 4.4.2.1
   DraytekVigor2765 Version-
DraytekVigor2765ax Firmware Version < 4.4.2.1
   DraytekVigor2765ax Version-
DraytekVigor2765ac Firmware Version < 4.4.2.1
   DraytekVigor2765ac Version-
DraytekVigor2765va Firmware Version < 4.4.2.1
   DraytekVigor2765va Version-
DraytekVigor2763 Firmware Version < 4.4.2.2
   DraytekVigor2763 Version-
DraytekVigor2763ac Firmware Version < 4.4.2.2
   DraytekVigor2763ac Version-
DraytekVigor2762 Firmware Version < 3.9.6.5
   DraytekVigor2762 Version-
DraytekVigor2762n Firmware Version < 3.9.6.5
   DraytekVigor2762n Version-
DraytekVigor2762ac Firmware Version < 3.9.6.5
   DraytekVigor2762ac Version-
DraytekVigor2762vac Firmware Version < 3.9.6.5
   DraytekVigor2762vac Version-
DraytekVigor2135 Firmware Version < 4.4.2.1
   DraytekVigor2135 Version-
DraytekVigor2135ax Firmware Version < 4.4.2.1
   DraytekVigor2135ax Version-
DraytekVigor2135ac Firmware Version < 4.4.2.1
   DraytekVigor2135ac Version-
DraytekVigor2135vac Firmware Version < 4.4.2.1
   DraytekVigor2135vac Version-
DraytekVigor2135fvac Firmware Version < 4.4.2.1
   DraytekVigor2135fvac Version-
DraytekVigor2133 Firmware Version < 3.9.6.5
   DraytekVigor2133 Version-
DraytekVigor2133n Firmware Version < 3.9.6.5
   DraytekVigor2133n Version-
DraytekVigor2133ac Firmware Version < 3.9.6.5
   DraytekVigor2133ac Version-
DraytekVigor2133vac Firmware Version < 3.9.6.5
   DraytekVigor2133vac Version-
DraytekVigor2133fvac Firmware Version < 3.9.6.5
   DraytekVigor2133fvac Version-
DraytekVigor166 Firmware Version < 4.2.4.1
   DraytekVigor166 Version-
DraytekVigor165 Firmware Version < 4.2.4.1
   DraytekVigor165 Version-
DraytekVigor130 Firmware Version < 3.8.5.1
   DraytekVigor130 Version-
DraytekVigornic 132 Firmware Version < 3.8.5.1
   DraytekVigornic 132 Version-
DraytekVigor3910 Firmware Version < 4.3.2.2
   DraytekVigor3910 Version-
DraytekVigor3220 Firmware Version < 3.9.7.4
   DraytekVigor3220 Version-
DraytekVigor2962 Firmware Version < 4.3.2.2
   DraytekVigor2962 Version-
DraytekVigor2962p Firmware Version < 4.3.2.2
   DraytekVigor2962p Version-
DraytekVigor1000b Firmware Version < 4.3.2.2
   DraytekVigor1000b Version-
DraytekVigor2952 Firmware Version < 3.9.7.4
   DraytekVigor2952 Version-
DraytekVigor2952p Firmware Version < 3.9.7.4
   DraytekVigor2952p Version-
DraytekVigor2927 Firmware Version < 4.4.2.3
   DraytekVigor2927 Version-
DraytekVigor2927ax Firmware Version < 4.4.2.3
   DraytekVigor2927ax Version-
DraytekVigor2927ac Firmware Version < 4.4.2.3
   DraytekVigor2927ac Version-
DraytekVigor2927vac Firmware Version < 4.4.2.3
   DraytekVigor2927vac Version-
DraytekVigor2927f Firmware Version < 4.4.2.3
   DraytekVigor2927f Version-
DraytekVigor2927l Firmware Version < 4.4.2.3
   DraytekVigor2927l Version-
DraytekVigor2927lac Firmware Version < 4.4.2.3
   DraytekVigor2927lac Version-
DraytekVigor2926 Firmware Version < 3.9.9.1
   DraytekVigor2926 Version-
DraytekVigor2926n Firmware Version < 3.9.9.1
   DraytekVigor2926n Version-
DraytekVigor2926ac Firmware Version < 3.9.9.1
   DraytekVigor2926ac Version-
DraytekVigor2926vac Firmware Version < 3.9.9.1
   DraytekVigor2926vac Version-
DraytekVigor2926l Firmware Version < 3.9.9.1
   DraytekVigor2926l Version-
DraytekVigor2926ln Firmware Version < 3.9.9.1
   DraytekVigor2926ln Version-
DraytekVigor2926lac Firmware Version < 3.9.9.1
   DraytekVigor2926lac Version-
DraytekVigor2925 Firmware Version < 3.9.4
   DraytekVigor2925 Version-
DraytekVigor2925n Firmware Version < 3.9.4
   DraytekVigor2925n Version-
DraytekVigor2925n-plus Firmware Version < 3.9.4
   DraytekVigor2925n-plus Version-
DraytekVigor2925vn-plus Firmware Version < 3.9.4
   DraytekVigor2925vn-plus Version-
DraytekVigor2925ac Firmware Version < 3.9.4
   DraytekVigor2925ac Version-
DraytekVigor2925vac Firmware Version < 3.9.4
   DraytekVigor2925vac Version-
DraytekVigor2925fn Firmware Version < 3.9.4
   DraytekVigor2925fn Version-
DraytekVigor2925l Firmware Version < 3.9.4
   DraytekVigor2925l Version-
DraytekVigor2925ln Firmware Version < 3.9.4
   DraytekVigor2925ln Version-
DraytekVigor2915 Firmware Version < 4.4.2.1
   DraytekVigor2915 Version-
DraytekVigor2915ac Firmware Version < 4.4.2.1
   DraytekVigor2915ac Version-
DraytekVigor2866 Firmware Version < 4.4.1.1
   DraytekVigor2866 Version-
DraytekVigor2866ax Firmware Version < 4.4.1.1
   DraytekVigor2866ax Version-
DraytekVigor2866ac Firmware Version < 4.4.1.1
   DraytekVigor2866ac Version-
DraytekVigor2866vac Firmware Version < 4.4.1.1
   DraytekVigor2866vac Version-
DraytekVigor2866l Firmware Version < 4.4.1.1
   DraytekVigor2866l Version-
DraytekVigor2866lac Firmware Version < 4.4.1.1
   DraytekVigor2866lac Version-
DraytekVigor2865 Firmware Version < 4.4.1.1
   DraytekVigor2865 Version-
DraytekVigor2865ax Firmware Version < 4.4.1.1
   DraytekVigor2865ax Version-
DraytekVigor2865ac Firmware Version < 4.4.1.1
   DraytekVigor2865ac Version-
DraytekVigor2865vac Firmware Version < 4.4.1.1
   DraytekVigor2865vac Version-
DraytekVigor2865l Firmware Version < 4.4.1.1
   DraytekVigor2865l Version-
DraytekVigor2865lac Firmware Version < 4.4.1.1
   DraytekVigor2865lac Version-
DraytekVigor2862 Firmware Version < 3.9.9.1
   DraytekVigor2862 Version-
DraytekVigor2862n Firmware Version < 3.9.9.1
   DraytekVigor2862n Version-
DraytekVigor2862ac Firmware Version < 3.9.9.1
   DraytekVigor2862ac Version-
DraytekVigor2862vac Firmware Version < 3.9.9.1
   DraytekVigor2862vac Version-
DraytekVigor2862b Firmware Version < 3.9.9.1
   DraytekVigor2862b Version-
DraytekVigor2862bn Firmware Version < 3.9.9.1
   DraytekVigor2862bn Version-
DraytekVigor2862l Firmware Version < 3.9.9.1
   DraytekVigor2862l Version-
DraytekVigor2862ln Firmware Version < 3.9.9.1
   DraytekVigor2862ln Version-
DraytekVigor2862lac Firmware Version < 3.9.9.1
   DraytekVigor2862lac Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.78% 0.823
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.1 2.8 2.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
134c704f-9b21-4f2e-91b3-4a467353bcc0 6.1 2.8 2.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.