CVE-2019-16534
 
Severity Score
6.1
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
On DrayTek Vigor2925 devices with firmware 3.8.4.3, XSS exists via a crafted WAN name on the General Setup screen. NOTE: this is an end-of-life product.
En los dispositivos On DrayTek Vigor2925 con versión de firmware 3.8.4.3, se presenta una vulnerabilidad de tipo XSS por medio de un nombre de WAN diseñado en la pantalla General Setup. NOTA: este es un producto al final de su vida útil.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2019-09-19 CVE Reserved
- 2019-09-20 CVE Published
- 2024-08-05 CVE Updated
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://www.draytek.com/about/security-advisory/urgent-security-updates-to-draytek-routers | X_refsource_misc | |
https://www.facebook.com/Huang.YuHsiang.Phone/posts/1815316691945755 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Draytek Search vendor "Draytek" | Vigor2925 Firmware Search vendor "Draytek" for product "Vigor2925 Firmware" | 3.8.4.3 Search vendor "Draytek" for product "Vigor2925 Firmware" and version "3.8.4.3" | - |
Affected
| in | Draytek Search vendor "Draytek" | Vigor 2925 Search vendor "Draytek" for product "Vigor 2925" | - | - |
Safe
|
Draytek Search vendor "Draytek" | Vigor2925 Firmware Search vendor "Draytek" for product "Vigor2925 Firmware" | 3.8.4.3 Search vendor "Draytek" for product "Vigor2925 Firmware" and version "3.8.4.3" | - |
Affected
| in | Draytek Search vendor "Draytek" | Vigor 2925n Search vendor "Draytek" for product "Vigor 2925n" | - | - |
Safe
|
Draytek Search vendor "Draytek" | Vigor2925 Firmware Search vendor "Draytek" for product "Vigor2925 Firmware" | 3.8.4.3 Search vendor "Draytek" for product "Vigor2925 Firmware" and version "3.8.4.3" | - |
Affected
| in | Draytek Search vendor "Draytek" | Vigor2925ac Search vendor "Draytek" for product "Vigor2925ac" | - | - |
Safe
|
Draytek Search vendor "Draytek" | Vigor2925 Firmware Search vendor "Draytek" for product "Vigor2925 Firmware" | 3.8.4.3 Search vendor "Draytek" for product "Vigor2925 Firmware" and version "3.8.4.3" | - |
Affected
| in | Draytek Search vendor "Draytek" | Vigor2925fn Search vendor "Draytek" for product "Vigor2925fn" | - | - |
Safe
|
Draytek Search vendor "Draytek" | Vigor2925 Firmware Search vendor "Draytek" for product "Vigor2925 Firmware" | 3.8.4.3 Search vendor "Draytek" for product "Vigor2925 Firmware" and version "3.8.4.3" | - |
Affected
| in | Draytek Search vendor "Draytek" | Vigor2925n-plus Search vendor "Draytek" for product "Vigor2925n-plus" | - | - |
Safe
|
Draytek Search vendor "Draytek" | Vigor2925 Firmware Search vendor "Draytek" for product "Vigor2925 Firmware" | 3.8.4.3 Search vendor "Draytek" for product "Vigor2925 Firmware" and version "3.8.4.3" | - |
Affected
| in | Draytek Search vendor "Draytek" | Vigor2925vac Search vendor "Draytek" for product "Vigor2925vac" | - | - |
Safe
|
Draytek Search vendor "Draytek" | Vigor2925 Firmware Search vendor "Draytek" for product "Vigor2925 Firmware" | 3.8.4.3 Search vendor "Draytek" for product "Vigor2925 Firmware" and version "3.8.4.3" | - |
Affected
| in | Draytek Search vendor "Draytek" | Vigor2925vn-plus Search vendor "Draytek" for product "Vigor2925vn-plus" | - | - |
Safe
|