Security Advisory
CVE-2024-41584
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
DrayTek Vigor3910 devices through 4.3.2.6 are vulnerable to reflected XSS by authenticated users, caused by missing validation of the sFormAuthStr parameter.