Medium severity5.4NVD Advisory· Published Oct 3, 2024· Updated Jun 17, 2026
CVE-2024-41587
CVE-2024-41587
Description
Stored XSS, by authenticated users, is caused by poor sanitization of the Login Page Greeting message in DrayTek Vigor310 devices through 4.3.2.6.
Affected products
26- cpe:2.3:o:draytek:vigor2620_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:draytek:vigorlte200_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:draytek:vigor2133_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:draytek:vigor2762_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:draytek:vigor2832_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:draytek:vigor2860_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:draytek:vigor2862_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:draytek:vigor2925_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:draytek:vigor2926_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:draytek:vigor2952_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:draytek:vigor3220_firmware:*:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
2- www.forescout.com/resources/draybreak-draytek-research/nvdMitigationTechnical DescriptionThird Party Advisory
- www.forescout.com/resources/draytek14-vulnerabilitiesnvdBroken Link
News mentions
0No linked articles in our index yet.