vendor:
VigorAP 1000C
by:
Vulnerability Laboratory
4.0
CVSS
MEDIUM
Persistent XSS
79
CWE
Product Name: VigorAP 1000C
Affected Version From: VigorAP 1000C | 1.3.2
Affected Version To: VigorAP 920R Series | 1.3.0
Patch Exists: YES
Related CWE: N/A
CPE: h:draytek:vigorap_1000c
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: All other VigorAP Series with Radius Module
2020
Draytek VigorAP 1000C – Persistent Cross-Site Scripting
A persistent input validation vulnerability has been discovered in the official Draytek VigorAP product series application. The vulnerability allows remote attackers to inject own malicious script codes with persistent attack vector to compromise browser to web-application requests from the application-side. The persistent input validation web vulnerability is located in the username input field of the RADIUS Setting - RADIUS Server Configuration module. Remote attackers with limited access are able to inject own malicious persistent script codes as username.
Mitigation:
Update to the latest version