DrayTek Alert
2738Warning Date
Severity Level
Warning Number
Target Sector
2 March, 2023
● High
2023-5485
All
Draytek has released security update to address a vulnerability in the following product:
- Vigor3910
- Vigor3220 Series
- Vigor2962 Series
- Vigor1000B
- Vigor2952 / 2952P
- Vigor2927 Series
- Vigor2927 LTE Series
- Vigor2926 Series
- Vigor2926 LTE Series
- Vigor2925 Series
- Vigor2925 LTE Series
- Vigor2915 Series
- Vigor2866 Series
- Vigor2866 LTE Series
- Vigor2865 Series
- Vigor2865 LTE Series
- Vigor2862 Series
- Vigor2862 LTE Series
- Vigor2860 Series
- Vigor2860 LTE Series
- Vigor2832 Series
- Vigor2766 Series
- Vigor2765 Series
- Vigor2763 Series
- Vigor2762 Series
- Vigor2135 Series
- Vigor2133 Series
- Vigor166
- Vigor165
- Vigor130
- VigorNIC 132
Attacker could exploit this vulnerability by conducting a cross-site scripting (XSS) attack.
The CERT team encourages users to review DrayTek security advisory and apply the necessary update:
- https://www.draytek.com/about/security-advisory/cross-site-scripting-vulnerability-(cve-2023-23313)/