Security Advisory

CVE-2024-41584

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2024-10-03 00:00:00
Last updated 2024-10-03 18:33:32
Assigner mitre
State PUBLISHED

Description

DrayTek Vigor3910 devices through 4.3.2.6 are vulnerable to reflected XSS by authenticated users, caused by missing validation of the sFormAuthStr parameter.