Medium severity5.4NVD Advisory· Published Oct 22, 2021· Updated Jun 17, 2026
CVE-2020-28968
CVE-2020-28968
Description
Draytek VigorAP 1000C contains a stored cross-site scripting (XSS) vulnerability in the RADIUS Setting - RADIUS Server Configuration module. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the username input field.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
15- cpe:2.3:o:draytek:vigorap_1000c_firmware:1.3.2:*:*:*:*:*:*:*
- cpe:2.3:o:draytek:vigorap_700_firmware:1.11:*:*:*:*:*:*:*
- cpe:2.3:o:draytek:vigorap_710_firmware:1.2.5:*:*:*:*:*:*:*
- cpe:2.3:o:draytek:vigorap_800_firmware:1.1.4:*:*:*:*:*:*:*
- cpe:2.3:o:draytek:vigorap_802_firmware:1.3.2:*:*:*:*:*:*:*
- cpe:2.3:o:draytek:vigorap_810_firmware:1.2.5:*:*:*:*:*:*:*
- cpe:2.3:o:draytek:vigorap_900_firmware:1.2.0:*:*:*:*:*:*:*
- cpe:2.3:o:draytek:vigorap_902_firmware:1.2.5:*:*:*:*:*:*:*
- cpe:2.3:o:draytek:vigorap_903_firmware:1.3.1:*:*:*:*:*:*:*
- cpe:2.3:o:draytek:vigorap_910c_firmware:1.2.5:*:*:*:*:*:*:*
- cpe:2.3:o:draytek:vigorap_912c_firmware:1.3.2:*:*:*:*:*:*:*
- cpe:2.3:o:draytek:vigorap_918r_firmware:1.3.2:*:*:*:*:*:*:*
- cpe:2.3:o:draytek:vigorap_920r_firmware:1.3.0:*:*:*:*:*:*:*
- Draytek/VigorAP 1000Cdescription
Patches
Vulnerability mechanics
References
1- www.vulnerability-lab.com/get_content.phpnvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.