Vulnerability Description
The DrayTek Vigor 2700 router 2.8.3 allows remote attackers to execute arbitrary JavaScript code, and modify settings or the DNS cache, via a crafted SSID value that is not properly handled during insertion into the sWlessSurvey value in variables.js.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Draytek | Vigor 2700 Router Firmware | 2.8.3 |
| Draytek | Vigor 2700 Router | - |
Related Weaknesses (CWE)
References
- http://www.kb.cert.org/vuls/id/101462US Government Resource
- http://www.kb.cert.org/vuls/id/101462US Government Resource
FAQ
What is CVE-2013-5703?
CVE-2013-5703 is a vulnerability with a CVSS score of 6.8 (MEDIUM). The DrayTek Vigor 2700 router 2.8.3 allows remote attackers to execute arbitrary JavaScript code, and modify settings or the DNS cache, via a crafted SSID value that is not properly handled during ins...
How severe is CVE-2013-5703?
CVE-2013-5703 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2013-5703?
Check the references section above for vendor advisories and patch information. Affected products include: Draytek Vigor 2700 Router Firmware, Draytek Vigor 2700 Router.