VendorsDrayTekvigor2925_firmware3.8.4.3
Vulnerabilities

DrayTek Vigor2925 Firmware 3.8.4.3

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2019-16533
On DrayTek Vigor2925 devices with firmware 3.8.4.3, Incorrect Access Control exists in loginset.htm, and can be used to trigger XSS. NOTE: this is an end-of-life product.
Published 2019-09-20 · Modified
6.1EPSS 0.008
CVE-2019-16534
On DrayTek Vigor2925 devices with firmware 3.8.4.3, XSS exists via a crafted WAN name on the General Setup screen. NOTE: this is an end-of-life product.
Published 2019-09-20 · Modified
6.1EPSS 0.008