ZeroHour

CVE-2024-41584

CVSS 3.1
4.7 medium
EPSS
<1%p21
Published
()
Modified
Description

DrayTek Vigor3910 devices through 4.3.2.6 are vulnerable to reflected XSS by authenticated users, caused by missing validation of the sFormAuthStr parameter.

Vendors
draytek
Products
vigor3910 firmware
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N

In the news