Vulnerability Description
Draytek VigorAP 1000C contains a stored cross-site scripting (XSS) vulnerability in the RADIUS Setting - RADIUS Server Configuration module. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the username input field.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Draytek | Vigorap 1000C Firmware | 1.3.2 |
| Draytek | Vigorap 1000C | - |
| Draytek | Vigorap 700 Firmware | 1.11 |
| Draytek | Vigorap 700 | - |
| Draytek | Vigorap 710 Firmware | 1.2.5 |
| Draytek | Vigorap 710 | - |
| Draytek | Vigorap 800 Firmware | 1.1.4 |
| Draytek | Vigorap 800 | - |
| Draytek | Vigorap 802 Firmware | 1.3.2 |
| Draytek | Vigorap 802 | - |
| Draytek | Vigorap 810 Firmware | 1.2.5 |
| Draytek | Vigorap 810 | - |
| Draytek | Vigorap 900 Firmware | 1.2.0 |
| Draytek | Vigorap 900 | - |
| Draytek | Vigorap 902 Firmware | 1.2.5 |
| Draytek | Vigorap 902 | - |
| Draytek | Vigorap 903 Firmware | 1.3.1 |
| Draytek | Vigorap 903 | - |
| Draytek | Vigorap 910C Firmware | 1.2.5 |
| Draytek | Vigorap 910C | - |
Related Weaknesses (CWE)
References
- https://www.vulnerability-lab.com/get_content.php?id=2244ExploitThird Party Advisory
- https://www.vulnerability-lab.com/get_content.php?id=2244ExploitThird Party Advisory
FAQ
What is CVE-2020-28968?
CVE-2020-28968 is a vulnerability with a CVSS score of 5.4 (MEDIUM). Draytek VigorAP 1000C contains a stored cross-site scripting (XSS) vulnerability in the RADIUS Setting - RADIUS Server Configuration module. This vulnerability allows attackers to execute arbitrary we...
How severe is CVE-2020-28968?
CVE-2020-28968 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-28968?
Check the references section above for vendor advisories and patch information. Affected products include: Draytek Vigorap 1000C Firmware, Draytek Vigorap 1000C, Draytek Vigorap 700 Firmware, Draytek Vigorap 700, Draytek Vigorap 710 Firmware.