MEDIUM
DrayTek Vigor3910 devices through 4.3.2.6 allow unauthenticated DOM-based reflected XSS
Published Oct 3, 2024
6.1
MEDIUMCVSS 3.1
EPSS 0.27%
Description
DrayTek Vigor3910 devices through 4.3.2.6 allow unauthenticated DOM-based reflected XSS.
Affected products
No data.
Configuration 1
AND
- n/a
Configuration 2
AND
- < 4.4.5.3
Configuration 3
AND
- < 4.4.5.2
Configuration 4
AND
- < 4.4.5.3
Configuration 5
AND
- < 4.4.5.2
Configuration 6
AND
- < 4.4.5.3
Configuration 7
AND
- < 4.4.5.3
Configuration 8
AND
- < 4.4.5.3
Configuration 9
AND
- < 4.2.7
Configuration 10
AND
OR
- < 4.3.2.8
- ≥ 4.4.0.0 · < 4.4.3.1
Running on/with
- n/a
Configuration 11
AND
- < 4.2.7
Configuration 12
AND
OR
- < 4.3.2.8
- ≥ 4.4.0.0 · < 4.4.3.1
Configuration 13
AND
OR
- < 4.3.2.8
- ≥ 4.4.0.0 · < 4.4.3.1
Configuration 14
AND
- < 4.3.6.1
Configuration 15
AND
- n/a
Running on/with
- n/a
Configuration 16
AND
- n/a
Configuration 17
AND
- n/a
Configuration 18
AND
- n/a
Configuration 19
AND
- n/a
Configuration 20
AND
- n/a
Configuration 21
AND
- n/a
Configuration 22
AND
- n/a
Configuration 23
AND
- n/a
Configuration 24
AND
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-39088 Advisory
- https://www.forescout.com/resources/draybreak-draytek-research/ MitigationTechnical DescriptionThird Party Advisory
- https://www.forescout.com/resources/draytek14-vulnerabilities Broken Link
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-39088 | Advisory | |
| https://www.forescout.com/resources/draybreak-draytek-research/ | MitigationTechnical DescriptionThird Party Advisory | |
| https://www.forescout.com/resources/draytek14-vulnerabilities | Broken Link |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Oct 3, 2024
Updated Mar 14, 2025
Reserved Jul 18, 2024
Link CVE-2024-41591
CISA Vulnrichment
Updated Oct 3, 2024
ENISA EUVD
EUVD-2024-39088 Assigner mitre
Published Oct 3, 2024
Updated Mar 14, 2025
Exploited since n/a
Link EUVD-2024-39088