Vulnerability Description
Stored XSS, by authenticated users, is caused by poor sanitization of the Login Page Greeting message in DrayTek Vigor310 devices through 4.3.2.6.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Draytek | Vigor3910 Firmware | < 4.3.2.8 |
| Draytek | Vigor3910 | - |
| Draytek | Vigor3912 Firmware | < 4.3.6.1 |
| Draytek | Vigor3912 | - |
| Draytek | Vigor2962 Firmware | < 4.3.2.8 |
| Draytek | Vigor2962 | - |
| Draytek | Vigor165 Firmware | < 4.2.7 |
| Draytek | Vigor165 | - |
| Draytek | Vigor1000B Firmware | < 4.3.2.8 |
| Draytek | Vigor1000B | - |
| Draytek | Vigor166 Firmware | < 4.2.7 |
| Draytek | Vigor166 | - |
| Draytek | Vigor2135 Firmware | < 4.4.5.3 |
| Draytek | Vigor2135 | - |
| Draytek | Vigor2763 Firmware | < 4.4.5.3 |
| Draytek | Vigor2763 | - |
| Draytek | Vigor2765 Firmware | < 4.4.5.3 |
| Draytek | Vigor2765 | - |
| Draytek | Vigor2865 Firmware | < 4.4.5.2 |
| Draytek | Vigor2865 | - |
Related Weaknesses (CWE)
References
- https://www.forescout.com/resources/draybreak-draytek-research/MitigationTechnical DescriptionThird Party Advisory
- https://www.forescout.com/resources/draytek14-vulnerabilitiesBroken Link
FAQ
What is CVE-2024-41587?
CVE-2024-41587 is a vulnerability with a CVSS score of 5.4 (MEDIUM). Stored XSS, by authenticated users, is caused by poor sanitization of the Login Page Greeting message in DrayTek Vigor310 devices through 4.3.2.6.
How severe is CVE-2024-41587?
CVE-2024-41587 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-41587?
Check the references section above for vendor advisories and patch information. Affected products include: Draytek Vigor3910 Firmware, Draytek Vigor3910, Draytek Vigor3912 Firmware, Draytek Vigor3912, Draytek Vigor2962 Firmware.