DrayTek Vigor routers 安全漏洞
CVE编号
CVE-2023-23313利用情况
暂无补丁情况
N/A披露时间
2023-03-04漏洞描述
Certain Draytek products are vulnerable to Cross Site Scripting (XSS) via the wlogin.cgi script and user_login.cgi script of the router's web application management portal. This affects Vigor3910, Vigor1000B, Vigor2962 v4.3.2.1; Vigor2865 and Vigor2866 v4.4.1.0; Vigor2927 v4.4.2.2; and Vigor2915, Vigor2765, Vigor2766, Vigor2135 v4.4.2.0; Vigor2763 v4.4.2.1; Vigor2862 and Vigor2926 v3.9.9.0; Vigor2925 v3.9.3; Vigor2952 and Vigor3220 v3.9.7.3; Vigor2133 and Vigor2762 v3.9.6.4; and Vigor2832 v3.9.6.2.解决建议
建议您更新当前系统或软件至最新版,完成漏洞的修复。
参考链接 |
|
---|---|
https://www.draytek.com/about/security-advisory/cross-site-scripting-vulnerab... | |
https://www.horizonconsulting.com/advisories23-Multiple-XSS-Stored-in-DrayTek... |
受影响软件情况
# | 类型 | 厂商 | 产品 | 版本 | 影响面 | ||||
1 | |||||||||
---|---|---|---|---|---|---|---|---|---|
运行在以下环境 | |||||||||
系统 | draytek | vigor130_firmware | * | Up to (excluding) 3.8.5.1 | |||||
运行在以下环境 | |||||||||
系统 | draytek | vigor165_firmware | * | Up to (excluding) 4.2.4.1 | |||||
运行在以下环境 | |||||||||
系统 | draytek | vigor166_firmware | * | Up to (excluding) 4.2.4.1 | |||||
运行在以下环境 | |||||||||
系统 | draytek | vigor2133ac_firmware | * | Up to (excluding) 3.9.6.5 | |||||
运行在以下环境 | |||||||||
系统 | draytek | vigor2133fvac_firmware | * | Up to (excluding) 3.9.6.5 | |||||
运行在以下环境 | |||||||||
系统 | draytek | vigor2133n_firmware | * | Up to (excluding) 3.9.6.5 | |||||
运行在以下环境 | |||||||||
系统 | draytek | vigor2133vac_firmware | * | Up to (excluding) 3.9.6.5 | |||||
运行在以下环境 | |||||||||
系统 | draytek | vigor2133_firmware | * | Up to (excluding) 3.9.6.5 | |||||
运行在以下环境 | |||||||||
系统 | draytek | vigor2135ac_firmware | * | Up to (excluding) 4.4.2.1 | |||||
运行在以下环境 | |||||||||
系统 | draytek | vigor2135ax_firmware | * | Up to (excluding) 4.4.2.1 | |||||
运行在以下环境 | |||||||||
系统 | draytek | vigor2135fvac_firmware | * | Up to (excluding) 4.4.2.1 | |||||
运行在以下环境 | |||||||||
系统 | draytek | vigor2135vac_firmware | * | Up to (excluding) 4.4.2.1 | |||||
运行在以下环境 | |||||||||
系统 | draytek | vigor2135_firmware | * | Up to (excluding) 4.4.2.1 | |||||
运行在以下环境 | |||||||||
系统 | draytek | vigor2762ac_firmware | * | Up to (excluding) 3.9.6.5 | |||||
运行在以下环境 | |||||||||
系统 | draytek | vigor2762n_firmware | * | Up to (excluding) 3.9.6.5 | |||||
运行在以下环境 | |||||||||
系统 | draytek | vigor2762vac_firmware | * | Up to (excluding) 3.9.6.5 | |||||
运行在以下环境 | |||||||||
系统 | draytek | vigor2762_firmware | * | Up to (excluding) 3.9.6.5 | |||||
运行在以下环境 | |||||||||
系统 | draytek | vigor2763ac_firmware | * | Up to (excluding) 4.4.2.2 | |||||
运行在以下环境 | |||||||||
系统 | draytek | vigor2763_firmware | * | Up to (excluding) 4.4.2.2 | |||||
运行在以下环境 | |||||||||
系统 | draytek | vigor2765ac_firmware | * | Up to (excluding) 4.4.2.1 | |||||
运行在以下环境 | |||||||||
系统 | draytek | vigor2765ax_firmware | * | Up to (excluding) 4.4.2.1 | |||||
运行在以下环境 | |||||||||
系统 | draytek | vigor2765va_firmware | * | Up to (excluding) 4.4.2.1 | |||||
运行在以下环境 | |||||||||
系统 | draytek | vigor2765_firmware | * | Up to (excluding) 4.4.2.1 | |||||
运行在以下环境 | |||||||||
系统 | draytek | vigor2766ac_firmware | * | Up to (excluding) 4.4.2.1 | |||||
运行在以下环境 | |||||||||
系统 | draytek | vigor2766ax_firmware | * | Up to (excluding) 4.4.2.1 | |||||
运行在以下环境 | |||||||||
系统 | draytek | vigor2766vac_firmware | * | Up to (excluding) 4.4.2.1 | |||||
运行在以下环境 | |||||||||
系统 | draytek | vigor2766_firmware | * | Up to (excluding) 4.4.2.1 | |||||
运行在以下环境 | |||||||||
系统 | draytek | vigor2832n_firmware | * | Up to (excluding) 3.9.6.3 | |||||
运行在以下环境 | |||||||||
系统 | draytek | vigor2832_firmware | * | Up to (excluding) 3.9.6.3 | |||||
运行在以下环境 | |||||||||
系统 | draytek | vigor2860ac_firmware | * | Up to (excluding) 3.9.4 | |||||
运行在以下环境 | |||||||||
系统 | draytek | vigor2860ln_firmware | * | Up to (excluding) 3.9.4 | |||||
运行在以下环境 | |||||||||
系统 | draytek | vigor2860l_firmware | * | Up to (excluding) 3.9.4 | |||||
运行在以下环境 | |||||||||
系统 | draytek | vigor2860n-plus_firmware | * | Up to (excluding) 3.9.4 | |||||
运行在以下环境 | |||||||||
系统 | draytek | vigor2860n_firmware | * | Up to (excluding) 3.9.4 | |||||
运行在以下环境 | |||||||||
系统 | draytek | vigor2860vac_firmware | * | Up to (excluding) 3.9.4 | |||||
运行在以下环境 | |||||||||
系统 | draytek | vigor2860vn-plus_firmware | * | Up to (excluding) 3.9.4 | |||||
运行在以下环境 | |||||||||
系统 | draytek | vigor2860_firmware | * | Up to (excluding) 3.9.4 | |||||
运行在以下环境 | |||||||||
系统 | draytek | vigornic_132_firmware | * | Up to (excluding) 3.8.5.1 | |||||
运行在以下环境 | |||||||||
系统 | draytek | virgor1000b_firmware | * | Up to (excluding) 4.3.2.2 | |||||
运行在以下环境 | |||||||||
系统 | draytek | virgor2862ac_firmware | * | Up to (excluding) 3.9.9.1 | |||||
运行在以下环境 | |||||||||
系统 | draytek | virgor2862bn_firmware | * | Up to (excluding) 3.9.9.1 | |||||
运行在以下环境 | |||||||||
系统 | draytek | virgor2862b_firmware | * | Up to (excluding) 3.9.9.1 | |||||
运行在以下环境 | |||||||||
系统 | draytek | virgor2862lac_firmware | * | Up to (excluding) 3.9.9.1 | |||||
运行在以下环境 | |||||||||
系统 | draytek | virgor2862ln_firmware | * | Up to (excluding) 3.9.9.1 | |||||
运行在以下环境 | |||||||||
系统 | draytek | virgor2862l_firmware | * | Up to (excluding) 3.9.9.1 | |||||
运行在以下环境 | |||||||||
系统 | draytek | virgor2862n_firmware | * | Up to (excluding) 3.9.9.1 | |||||
运行在以下环境 | |||||||||
系统 | draytek | virgor2862vac_firmware | * | Up to (excluding) 3.9.9.1 | |||||
运行在以下环境 | |||||||||
系统 | draytek | virgor2862_firmware | * | Up to (excluding) 3.9.9.1 | |||||
运行在以下环境 | |||||||||
系统 | draytek | virgor2865ac_firmware | * | Up to (excluding) 4.4.1.1 | |||||
运行在以下环境 | |||||||||
系统 | draytek | virgor2865ax_firmware | * | Up to (excluding) 4.4.1.1 | |||||
运行在以下环境 | |||||||||
系统 | draytek | virgor2865lac_firmware | * | Up to (excluding) 4.4.1.1 | |||||
运行在以下环境 | |||||||||
系统 | draytek | virgor2865l_firmware | * | Up to (excluding) 4.4.1.1 | |||||
运行在以下环境 | |||||||||
系统 | draytek | virgor2865vac_firmware | * | Up to (excluding) 4.4.1.1 | |||||
运行在以下环境 | |||||||||
系统 | draytek | virgor2865_firmware | * | Up to (excluding) 4.4.1.1 | |||||
运行在以下环境 | |||||||||
系统 | draytek | virgor2866ac_firmware | * | Up to (excluding) 4.4.1.1 | |||||
运行在以下环境 | |||||||||
系统 | draytek | virgor2866ax_firmware | * | Up to (excluding) 4.4.1.1 | |||||
运行在以下环境 | |||||||||
系统 | draytek | virgor2866lac_firmware | * | Up to (excluding) 4.4.1.1 | |||||
运行在以下环境 | |||||||||
系统 | draytek | virgor2866l_firmware | * | Up to (excluding) 4.4.1.1 | |||||
运行在以下环境 | |||||||||
系统 | draytek | virgor2866vac_firmware | * | Up to (excluding) 4.4.1.1 | |||||
运行在以下环境 | |||||||||
系统 | draytek | virgor2866_firmware | * | Up to (excluding) 4.4.1.1 | |||||
运行在以下环境 | |||||||||
系统 | draytek | virgor2915ac_firmware | * | Up to (excluding) 4.4.2.1 | |||||
运行在以下环境 | |||||||||
系统 | draytek | virgor2915_firmware | * | Up to (excluding) 4.4.2.1 | |||||
运行在以下环境 | |||||||||
系统 | draytek | virgor2925ac_firmware | * | Up to (excluding) 3.9.4 | |||||
运行在以下环境 | |||||||||
系统 | draytek | virgor2925fn_firmware | * | Up to (excluding) 3.9.4 | |||||
运行在以下环境 | |||||||||
系统 | draytek | virgor2925ln_firmware | * | Up to (excluding) 3.9.4 | |||||
运行在以下环境 | |||||||||
系统 | draytek | virgor2925l_firmware | * | Up to (excluding) 3.9.4 | |||||
运行在以下环境 | |||||||||
系统 | draytek | virgor2925n-plus_firmware | * | Up to (excluding) 3.9.4 | |||||
运行在以下环境 | |||||||||
系统 | draytek | virgor2925n_firmware | * | Up to (excluding) 3.9.4 | |||||
运行在以下环境 | |||||||||
系统 | draytek | virgor2925vac_firmware | * | Up to (excluding) 3.9.4 | |||||
运行在以下环境 | |||||||||
系统 | draytek | virgor2925vn-plus_firmware | * | Up to (excluding) 3.9.4 | |||||
运行在以下环境 | |||||||||
系统 | draytek | virgor2925_firmware | * | Up to (excluding) 3.9.4 | |||||
运行在以下环境 | |||||||||
系统 | draytek | virgor2926ac_firmware | * | Up to (excluding) 3.9.9.1 | |||||
运行在以下环境 | |||||||||
系统 | draytek | virgor2926lac_firmware | * | Up to (excluding) 3.9.9.1 | |||||
运行在以下环境 | |||||||||
系统 | draytek | virgor2926ln_firmware | * | Up to (excluding) 3.9.9.1 | |||||
运行在以下环境 | |||||||||
系统 | draytek | virgor2926l_firmware | * | Up to (excluding) 3.9.9.1 | |||||
运行在以下环境 | |||||||||
系统 | draytek | virgor2926n_firmware | * | Up to (excluding) 3.9.9.1 | |||||
运行在以下环境 | |||||||||
系统 | draytek | virgor2926vac_firmware | * | Up to (excluding) 3.9.9.1 | |||||
运行在以下环境 | |||||||||
系统 | draytek | virgor2926_firmware | * | Up to (excluding) 3.9.9.1 | |||||
运行在以下环境 | |||||||||
系统 | draytek | virgor2927ac_firmware | * | Up to (excluding) 4.4.2.3 | |||||
运行在以下环境 | |||||||||
系统 | draytek | virgor2927ax_firmware | * | Up to (excluding) 4.4.2.3 | |||||
运行在以下环境 | |||||||||
系统 | draytek | virgor2927f_firmware | * | Up to (excluding) 4.4.2.3 | |||||
运行在以下环境 | |||||||||
系统 | draytek | virgor2927lac_firmware | * | Up to (excluding) 4.4.2.3 | |||||
运行在以下环境 | |||||||||
系统 | draytek | virgor2927l_firmware | * | Up to (excluding) 4.4.2.3 | |||||
运行在以下环境 | |||||||||
系统 | draytek | virgor2927vac_firmware | * | Up to (excluding) 4.4.2.3 | |||||
运行在以下环境 | |||||||||
系统 | draytek | virgor2927_firmware | * | Up to (excluding) 4.4.2.3 | |||||
运行在以下环境 | |||||||||
系统 | draytek | virgor2952p_firmware | * | Up to (excluding) 3.9.7.4 | |||||
运行在以下环境 | |||||||||
系统 | draytek | virgor2952_firmware | * | Up to (excluding) 3.9.7.4 | |||||
运行在以下环境 | |||||||||
系统 | draytek | virgor2962p_firmware | * | Up to (excluding) 4.3.2.2 | |||||
运行在以下环境 | |||||||||
系统 | draytek | virgor2962_firmware | * | Up to (excluding) 4.3.2.2 | |||||
运行在以下环境 | |||||||||
系统 | draytek | virgor3220_firmware | * | Up to (excluding) 3.9.7.4 | |||||
运行在以下环境 | |||||||||
系统 | draytek | virgor3910_firmware | * | Up to (excluding) 4.3.2.2 | |||||
运行在以下环境 | |||||||||
硬件 | draytek | vigor130 | - | - | |||||
运行在以下环境 | |||||||||
硬件 | draytek | vigor165 | - | - | |||||
运行在以下环境 | |||||||||
硬件 | draytek | vigor166 | - | - | |||||
运行在以下环境 | |||||||||
硬件 | draytek | vigor2133 | - | - | |||||
运行在以下环境 | |||||||||
硬件 | draytek | vigor2133ac | - | - | |||||
运行在以下环境 | |||||||||
硬件 | draytek | vigor2133fvac | - | - | |||||
运行在以下环境 | |||||||||
硬件 | draytek | vigor2133n | - | - | |||||
运行在以下环境 | |||||||||
硬件 | draytek | vigor2133vac | - | - | |||||
运行在以下环境 | |||||||||
硬件 | draytek | vigor2135 | - | - | |||||
运行在以下环境 | |||||||||
硬件 | draytek | vigor2135ac | - | - | |||||
运行在以下环境 | |||||||||
硬件 | draytek | vigor2135ax | - | - | |||||
运行在以下环境 | |||||||||
硬件 | draytek | vigor2135fvac | - | - | |||||
运行在以下环境 | |||||||||
硬件 | draytek | vigor2135vac | - | - | |||||
运行在以下环境 | |||||||||
硬件 | draytek | vigor2762 | - | - | |||||
运行在以下环境 | |||||||||
硬件 | draytek | vigor2762ac | - | - | |||||
运行在以下环境 | |||||||||
硬件 | draytek | vigor2762n | - | - | |||||
运行在以下环境 | |||||||||
硬件 | draytek | vigor2762vac | - | - | |||||
运行在以下环境 | |||||||||
硬件 | draytek | vigor2763 | - | - | |||||
运行在以下环境 | |||||||||
硬件 | draytek | vigor2763ac | - | - | |||||
运行在以下环境 | |||||||||
硬件 | draytek | vigor2765 | - | - | |||||
运行在以下环境 | |||||||||
硬件 | draytek | vigor2765ac | - | - | |||||
运行在以下环境 | |||||||||
硬件 | draytek | vigor2765ax | - | - | |||||
运行在以下环境 | |||||||||
硬件 | draytek | vigor2765va | - | - | |||||
运行在以下环境 | |||||||||
硬件 | draytek | vigor2766 | - | - | |||||
运行在以下环境 | |||||||||
硬件 | draytek | vigor2766ac | - | - | |||||
运行在以下环境 | |||||||||
硬件 | draytek | vigor2766ax | - | - | |||||
运行在以下环境 | |||||||||
硬件 | draytek | vigor2766vac | - | - | |||||
运行在以下环境 | |||||||||
硬件 | draytek | vigor2832 | - | - | |||||
运行在以下环境 | |||||||||
硬件 | draytek | vigor2832n | - | - | |||||
运行在以下环境 | |||||||||
硬件 | draytek | vigor2860 | - | - | |||||
运行在以下环境 | |||||||||
硬件 | draytek | vigor2860ac | - | - | |||||
运行在以下环境 | |||||||||
硬件 | draytek | vigor2860l | - | - | |||||
运行在以下环境 | |||||||||
硬件 | draytek | vigor2860ln | - | - | |||||
运行在以下环境 | |||||||||
硬件 | draytek | vigor2860n | - | - | |||||
运行在以下环境 | |||||||||
硬件 | draytek | vigor2860n-plus | - | - | |||||
运行在以下环境 | |||||||||
硬件 | draytek | vigor2860vac | - | - | |||||
运行在以下环境 | |||||||||
硬件 | draytek | vigor2860vn-plus | - | - | |||||
运行在以下环境 | |||||||||
硬件 | draytek | vigornic_132 | - | - | |||||
运行在以下环境 | |||||||||
硬件 | draytek | virgor1000b | - | - | |||||
运行在以下环境 | |||||||||
硬件 | draytek | virgor2862 | - | - | |||||
运行在以下环境 | |||||||||
硬件 | draytek | virgor2862ac | - | - | |||||
运行在以下环境 | |||||||||
硬件 | draytek | virgor2862b | - | - | |||||
运行在以下环境 | |||||||||
硬件 | draytek | virgor2862bn | - | - | |||||
运行在以下环境 | |||||||||
硬件 | draytek | virgor2862l | - | - | |||||
运行在以下环境 | |||||||||
硬件 | draytek | virgor2862lac | - | - | |||||
运行在以下环境 | |||||||||
硬件 | draytek | virgor2862ln | - | - | |||||
运行在以下环境 | |||||||||
硬件 | draytek | virgor2862n | - | - | |||||
运行在以下环境 | |||||||||
硬件 | draytek | virgor2862vac | - | - | |||||
运行在以下环境 | |||||||||
硬件 | draytek | virgor2865 | - | - | |||||
运行在以下环境 | |||||||||
硬件 | draytek | virgor2865ac | - | - | |||||
运行在以下环境 | |||||||||
硬件 | draytek | virgor2865ax | - | - | |||||
运行在以下环境 | |||||||||
硬件 | draytek | virgor2865l | - | - | |||||
运行在以下环境 | |||||||||
硬件 | draytek | virgor2865lac | - | - | |||||
运行在以下环境 | |||||||||
硬件 | draytek | virgor2865vac | - | - | |||||
运行在以下环境 | |||||||||
硬件 | draytek | virgor2866 | - | - | |||||
运行在以下环境 | |||||||||
硬件 | draytek | virgor2866ac | - | - | |||||
运行在以下环境 | |||||||||
硬件 | draytek | virgor2866ax | - | - | |||||
运行在以下环境 | |||||||||
硬件 | draytek | virgor2866l | - | - | |||||
运行在以下环境 | |||||||||
硬件 | draytek | virgor2866lac | - | - | |||||
运行在以下环境 | |||||||||
硬件 | draytek | virgor2866vac | - | - | |||||
运行在以下环境 | |||||||||
硬件 | draytek | virgor2915 | - | - | |||||
运行在以下环境 | |||||||||
硬件 | draytek | virgor2915ac | - | - | |||||
运行在以下环境 | |||||||||
硬件 | draytek | virgor2925 | - | - | |||||
运行在以下环境 | |||||||||
硬件 | draytek | virgor2925ac | - | - | |||||
运行在以下环境 | |||||||||
硬件 | draytek | virgor2925fn | - | - | |||||
运行在以下环境 | |||||||||
硬件 | draytek | virgor2925l | - | - | |||||
运行在以下环境 | |||||||||
硬件 | draytek | virgor2925ln | - | - | |||||
运行在以下环境 | |||||||||
硬件 | draytek | virgor2925n | - | - | |||||
运行在以下环境 | |||||||||
硬件 | draytek | virgor2925n-plus | - | - | |||||
运行在以下环境 | |||||||||
硬件 | draytek | virgor2925vac | - | - | |||||
运行在以下环境 | |||||||||
硬件 | draytek | virgor2925vn-plus | - | - | |||||
运行在以下环境 | |||||||||
硬件 | draytek | virgor2926 | - | - | |||||
运行在以下环境 | |||||||||
硬件 | draytek | virgor2926ac | - | - | |||||
运行在以下环境 | |||||||||
硬件 | draytek | virgor2926l | - | - | |||||
运行在以下环境 | |||||||||
硬件 | draytek | virgor2926lac | - | - | |||||
运行在以下环境 | |||||||||
硬件 | draytek | virgor2926ln | - | - | |||||
运行在以下环境 | |||||||||
硬件 | draytek | virgor2926n | - | - | |||||
运行在以下环境 | |||||||||
硬件 | draytek | virgor2926vac | - | - | |||||
运行在以下环境 | |||||||||
硬件 | draytek | virgor2927 | - | - | |||||
运行在以下环境 | |||||||||
硬件 | draytek | virgor2927ac | - | - | |||||
运行在以下环境 | |||||||||
硬件 | draytek | virgor2927ax | - | - | |||||
运行在以下环境 | |||||||||
硬件 | draytek | virgor2927f | - | - | |||||
运行在以下环境 | |||||||||
硬件 | draytek | virgor2927l | - | - | |||||
运行在以下环境 | |||||||||
硬件 | draytek | virgor2927lac | - | - | |||||
运行在以下环境 | |||||||||
硬件 | draytek | virgor2927vac | - | - | |||||
运行在以下环境 | |||||||||
硬件 | draytek | virgor2952 | - | - | |||||
运行在以下环境 | |||||||||
硬件 | draytek | virgor2952p | - | - | |||||
运行在以下环境 | |||||||||
硬件 | draytek | virgor2962 | - | - | |||||
运行在以下环境 | |||||||||
硬件 | draytek | virgor2962p | - | - | |||||
运行在以下环境 | |||||||||
硬件 | draytek | virgor3220 | - | - | |||||
运行在以下环境 | |||||||||
硬件 | draytek | virgor3910 | - | - | |||||
- 攻击路径 网络
- 攻击复杂度 低
- 权限要求 无
- 影响范围 已更改
- 用户交互 需要
- 可用性 无
- 保密性 低
- 完整性 低
CWE-ID | 漏洞类型 |
CWE-79 | 在Web页面生成时对输入的转义处理不恰当(跨站脚本) |
Exp相关链接

版权声明
本站原创文章转载请注明文章出处及链接,谢谢合作!
评论