Unknown
CVE-2023-23313
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below:
Add References:
CVE-2023-23313
MITRE ATT&CK
Collection
Command and Control
Credential Access
Defense Evasion
Discovery
Execution
Exfiltration
Impact
Initial Access
Lateral Movement
Persistence
Privilege Escalation
Topic Tags
Description
Certain Draytek products are vulnerable to Cross Site Scripting (XSS) via the wlogin.cgi script and user_login.cgi script of the router’s web application management portal. This affects Vigor3910, Vigor1000B, Vigor2962 v4.3.2.1; Vigor2865 and Vigor2866 v4.4.1.0; Vigor2927 v4.4.2.2; and Vigor2915, Vigor2765, Vigor2766, Vigor2135 v4.4.2.0; Vigor2763 v4.4.2.1; Vigor2862 and Vigor2926 v3.9.9.0; Vigor2925 v3.9.3; Vigor2952 and Vigor3220 v3.9.7.3; Vigor2133 and Vigor2762 v3.9.6.4; and Vigor2832 v3.9.6.2.
Add Assessment
No one has assessed this topic. Be the first to add your voice to the community.
CVSS V3 Severity and Metrics
General Information
Vendors
Products
- vigor130 firmware,
- vigor165 firmware,
- vigor166 firmware,
- vigor2133 firmware,
- vigor2133ac firmware,
- vigor2133fvac firmware,
- vigor2133n firmware,
- vigor2133vac firmware,
- vigor2135 firmware,
- vigor2135ac firmware,
- vigor2135ax firmware,
- vigor2135fvac firmware,
- vigor2135vac firmware,
- vigor2762 firmware,
- vigor2762ac firmware,
- vigor2762n firmware,
- vigor2762vac firmware,
- vigor2763 firmware,
- vigor2763ac firmware,
- vigor2765 firmware,
- vigor2765ac firmware,
- vigor2765ax firmware,
- vigor2765va firmware,
- vigor2766 firmware,
- vigor2766ac firmware,
- vigor2766ax firmware,
- vigor2766vac firmware,
- vigor2832 firmware,
- vigor2832n firmware,
- vigor2860 firmware,
- vigor2860ac firmware,
- vigor2860l firmware,
- vigor2860ln firmware,
- vigor2860n firmware,
- vigor2860n-plus firmware,
- vigor2860vac firmware,
- vigor2860vn-plus firmware,
- vigornic 132 firmware,
- virgor1000b firmware,
- virgor2862 firmware,
- virgor2862ac firmware,
- virgor2862b firmware,
- virgor2862bn firmware,
- virgor2862l firmware,
- virgor2862lac firmware,
- virgor2862ln firmware,
- virgor2862n firmware,
- virgor2862vac firmware,
- virgor2865 firmware,
- virgor2865ac firmware,
- virgor2865ax firmware,
- virgor2865l firmware,
- virgor2865lac firmware,
- virgor2865vac firmware,
- virgor2866 firmware,
- virgor2866ac firmware,
- virgor2866ax firmware,
- virgor2866l firmware,
- virgor2866lac firmware,
- virgor2866vac firmware,
- virgor2915 firmware,
- virgor2915ac firmware,
- virgor2925 firmware,
- virgor2925ac firmware,
- virgor2925fn firmware,
- virgor2925l firmware,
- virgor2925ln firmware,
- virgor2925n firmware,
- virgor2925n-plus firmware,
- virgor2925vac firmware,
- virgor2925vn-plus firmware,
- virgor2926 firmware,
- virgor2926ac firmware,
- virgor2926l firmware,
- virgor2926lac firmware,
- virgor2926ln firmware,
- virgor2926n firmware,
- virgor2926vac firmware,
- virgor2927 firmware,
- virgor2927ac firmware,
- virgor2927ax firmware,
- virgor2927f firmware,
- virgor2927l firmware,
- virgor2927lac firmware,
- virgor2927vac firmware,
- virgor2952 firmware,
- virgor2952p firmware,
- virgor2962 firmware,
- virgor2962p firmware,
- virgor3220 firmware,
- virgor3910 firmware
References
Additional Info
Technical Analysis
Report as Emergent Threat Response
Report as Zero-day Exploit
Report as Exploited in the Wild
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below: