Draytek VigorAP 1000C contains a stored cross-site scripting (XSS) vulnerability in the RADIUS Setting - RADIUS Server Configuration module. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the username input field.
References
Link | Resource |
---|---|
https://www.vulnerability-lab.com/get_content.php?id=2244 | Exploit Third Party Advisory |
https://www.vulnerability-lab.com/get_content.php?id=2244 | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
Configuration 5 (hide)
AND |
|
Configuration 6 (hide)
AND |
|
Configuration 7 (hide)
AND |
|
Configuration 8 (hide)
AND |
|
Configuration 9 (hide)
AND |
|
Configuration 10 (hide)
AND |
|
Configuration 11 (hide)
AND |
|
Configuration 12 (hide)
AND |
|
Configuration 13 (hide)
AND |
|
History
21 Nov 2024, 05:23
Type | Values Removed | Values Added |
---|---|---|
References | () https://www.vulnerability-lab.com/get_content.php?id=2244 - Exploit, Third Party Advisory |
28 Oct 2021, 16:48
Type | Values Removed | Values Added |
---|---|---|
References | (MISC) https://www.vulnerability-lab.com/get_content.php?id=2244 - Exploit, Third Party Advisory | |
CPE | cpe:2.3:o:draytek:vigorap_810_firmware:1.2.5:*:*:*:*:*:*:* cpe:2.3:h:draytek:vigorap_920r:-:*:*:*:*:*:*:* cpe:2.3:o:draytek:vigorap_902_firmware:1.2.5:*:*:*:*:*:*:* cpe:2.3:h:draytek:vigorap_710:-:*:*:*:*:*:*:* cpe:2.3:h:draytek:vigorap_810:-:*:*:*:*:*:*:* cpe:2.3:h:draytek:vigorap_1000c:-:*:*:*:*:*:*:* cpe:2.3:h:draytek:vigorap_918r:-:*:*:*:*:*:*:* cpe:2.3:o:draytek:vigorap_903_firmware:1.3.1:*:*:*:*:*:*:* cpe:2.3:o:draytek:vigorap_920r_firmware:1.3.0:*:*:*:*:*:*:* cpe:2.3:h:draytek:vigorap_903:-:*:*:*:*:*:*:* cpe:2.3:h:draytek:vigorap_912c:-:*:*:*:*:*:*:* cpe:2.3:h:draytek:vigorap_902:-:*:*:*:*:*:*:* cpe:2.3:o:draytek:vigorap_910c_firmware:1.2.5:*:*:*:*:*:*:* cpe:2.3:o:draytek:vigorap_900_firmware:1.2.0:*:*:*:*:*:*:* cpe:2.3:h:draytek:vigorap_900:-:*:*:*:*:*:*:* cpe:2.3:h:draytek:vigorap_910c:-:*:*:*:*:*:*:* cpe:2.3:o:draytek:vigorap_912c_firmware:1.3.2:*:*:*:*:*:*:* cpe:2.3:o:draytek:vigorap_918r_firmware:1.3.2:*:*:*:*:*:*:* cpe:2.3:h:draytek:vigorap_800:-:*:*:*:*:*:*:* cpe:2.3:o:draytek:vigorap_1000c_firmware:1.3.2:*:*:*:*:*:*:* cpe:2.3:o:draytek:vigorap_710_firmware:1.2.5:*:*:*:*:*:*:* cpe:2.3:h:draytek:vigorap_802:-:*:*:*:*:*:*:* cpe:2.3:o:draytek:vigorap_800_firmware:1.1.4:*:*:*:*:*:*:* cpe:2.3:o:draytek:vigorap_802_firmware:1.3.2:*:*:*:*:*:*:* cpe:2.3:o:draytek:vigorap_700_firmware:1.11:*:*:*:*:*:*:* cpe:2.3:h:draytek:vigorap_700:-:*:*:*:*:*:*:* |
|
CVSS |
v2 : v3 : |
v2 : 3.5
v3 : 5.4 |
CWE | CWE-79 |
22 Oct 2021, 20:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2021-10-22 20:15
Updated : 2024-11-21 05:23
NVD link : CVE-2020-28968
Mitre link : CVE-2020-28968
CVE.ORG link : CVE-2020-28968
JSON object : View
Products Affected
draytek
- vigorap_910c_firmware
- vigorap_810
- vigorap_912c_firmware
- vigorap_802_firmware
- vigorap_920r_firmware
- vigorap_800
- vigorap_810_firmware
- vigorap_902
- vigorap_800_firmware
- vigorap_903
- vigorap_700
- vigorap_802
- vigorap_903_firmware
- vigorap_900_firmware
- vigorap_918r
- vigorap_900
- vigorap_910c
- vigorap_1000c
- vigorap_920r
- vigorap_902_firmware
- vigorap_912c
- vigorap_918r_firmware
- vigorap_710_firmware
- vigorap_1000c_firmware
- vigorap_710
- vigorap_700_firmware
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')