VendorsDrayTekvigorap_910cany version
Vulnerabilities

DrayTek VigorAP 910C any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2017-11649
Cross-site request forgery (CSRF) vulnerability in DrayTek Vigor AP910C devices with firmware 1.2.0_RC3 build r6594 allows remote attackers to hijack the authentication of unspecified users for requests that enable SNMP on the remote device via vectors involving goform/setSnmp.
Published 2018-03-06 · Modified
8.8EPSS 0.007
CVE-2020-3932
Draytek VigorAP910C - Information Leakage
Published 2020-04-15 · Modified
7.5EPSS 0.011
CVE-2017-11650
Cross-site scripting (XSS) vulnerability in DrayTek Vigor AP910C devices with firmware 1.2.0_RC3 build r6594 allows remote attackers to inject arbitrary web script or HTML via vectors involving home.asp.
Published 2018-03-06 · Modified
6.1EPSS 0.009
CVE-2020-28968
Draytek VigorAP 1000C contains a stored cross-site scripting (XSS) vulnerability in the RADIUS Setting - RADIUS Server Configuration module. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the username input field.
Published 2021-10-22 · Modified
5.4EPSS 0.006