Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-23313


Certain Draytek products are vulnerable to Cross Site Scripting (XSS) via the wlogin.cgi script and user_login.cgi script of the router's web application management portal. This affects Vigor3910, Vigor1000B, Vigor2962 v4.3.2.1; Vigor2865 and Vigor2866 v4.4.1.0; Vigor2927 v4.4.2.2; and Vigor2915, Vigor2765, Vigor2766, Vigor2135 v4.4.2.0; Vigor2763 v4.4.2.1; Vigor2862 and Vigor2926 v3.9.9.0; Vigor2925 v3.9.3; Vigor2952 and Vigor3220 v3.9.7.3; Vigor2133 and Vigor2762 v3.9.6.4; and Vigor2832 v3.9.6.2.


Security Impact Summary

This vulnerability carries a MEDIUM severity rating with a CVSS v3.1 score of 6.1, indicating it can be exploited remotely over the network with relatively low complexity though user interaction is required and does not require pre-existing privileges . The vulnerability impacts limited data confidentiality, limited integrity, for affected systems. Impacting 182 products from draytek, from draytek, from draytek and 179 others, organizations running these solutions should prioritize assessment and patching.

Historical Context

Reported in 2023, this vulnerability emerged during an era marked by increased sophistication in supply chain attacks, cloud infrastructure vulnerabilities, and software-as-a-service (SaaS) security challenges. Security practices during this period emphasized zero-trust architectures, container security, and API protection.


Published

2023-03-03T22:15:09.690

Last Modified

2025-10-07T19:00:07.737

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 6.1 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-79
  • Type: Secondary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System draytek vigor2860_firmware < 3.9.4 Yes
Hardware draytek vigor2860 - No
Operating System draytek vigor2860n_firmware < 3.9.4 Yes
Hardware draytek vigor2860n - No
Operating System draytek vigor2860n-plus_firmware < 3.9.4 Yes
Hardware draytek vigor2860n-plus - No
Operating System draytek vigor2860vn-plus_firmware < 3.9.4 Yes
Hardware draytek vigor2860vn-plus - No
Operating System draytek vigor2860ac_firmware < 3.9.4 Yes
Hardware draytek vigor2860ac - No
Operating System draytek vigor2860vac_firmware < 3.9.4 Yes
Hardware draytek vigor2860vac - No
Operating System draytek vigor2860l_firmware < 3.9.4 Yes
Hardware draytek vigor2860l - No
Operating System draytek vigor2860ln_firmware < 3.9.4 Yes
Hardware draytek vigor2860ln - No
Operating System draytek vigor2832_firmware < 3.9.6.3 Yes
Hardware draytek vigor2832 - No
Operating System draytek vigor2832n_firmware < 3.9.6.3 Yes
Hardware draytek vigor2832n - No
Operating System draytek vigor2766_firmware < 4.4.2.1 Yes
Hardware draytek vigor2766 - No
Operating System draytek vigor2766ax_firmware < 4.4.2.1 Yes
Hardware draytek vigor2766ax - No
Operating System draytek vigor2766ac_firmware < 4.4.2.1 Yes
Hardware draytek vigor2766ac - No
Operating System draytek vigor2766vac_firmware < 4.4.2.1 Yes
Hardware draytek vigor2766vac - No
Operating System draytek vigor2765_firmware < 4.4.2.1 Yes
Hardware draytek vigor2765 - No
Operating System draytek vigor2765ax_firmware < 4.4.2.1 Yes
Hardware draytek vigor2765ax - No
Operating System draytek vigor2765ac_firmware < 4.4.2.1 Yes
Hardware draytek vigor2765ac - No
Operating System draytek vigor2765va_firmware < 4.4.2.1 Yes
Hardware draytek vigor2765va - No
Operating System draytek vigor2763_firmware < 4.4.2.2 Yes
Hardware draytek vigor2763 - No
Operating System draytek vigor2763ac_firmware < 4.4.2.2 Yes
Hardware draytek vigor2763ac - No
Operating System draytek vigor2762_firmware < 3.9.6.5 Yes
Hardware draytek vigor2762 - No
Operating System draytek vigor2762n_firmware < 3.9.6.5 Yes
Hardware draytek vigor2762n - No
Operating System draytek vigor2762ac_firmware < 3.9.6.5 Yes
Hardware draytek vigor2762ac - No
Operating System draytek vigor2762vac_firmware < 3.9.6.5 Yes
Hardware draytek vigor2762vac - No
Operating System draytek vigor2135_firmware < 4.4.2.1 Yes
Hardware draytek vigor2135 - No
Operating System draytek vigor2135ax_firmware < 4.4.2.1 Yes
Hardware draytek vigor2135ax - No
Operating System draytek vigor2135ac_firmware < 4.4.2.1 Yes
Hardware draytek vigor2135ac - No
Operating System draytek vigor2135vac_firmware < 4.4.2.1 Yes
Hardware draytek vigor2135vac - No
Operating System draytek vigor2135fvac_firmware < 4.4.2.1 Yes
Hardware draytek vigor2135fvac - No
Operating System draytek vigor2133_firmware < 3.9.6.5 Yes
Hardware draytek vigor2133 - No
Operating System draytek vigor2133n_firmware < 3.9.6.5 Yes
Hardware draytek vigor2133n - No
Operating System draytek vigor2133ac_firmware < 3.9.6.5 Yes
Hardware draytek vigor2133ac - No
Operating System draytek vigor2133vac_firmware < 3.9.6.5 Yes
Hardware draytek vigor2133vac - No
Operating System draytek vigor2133fvac_firmware < 3.9.6.5 Yes
Hardware draytek vigor2133fvac - No
Operating System draytek vigor166_firmware < 4.2.4.1 Yes
Hardware draytek vigor166 - No
Operating System draytek vigor165_firmware < 4.2.4.1 Yes
Hardware draytek vigor165 - No
Operating System draytek vigor130_firmware < 3.8.5.1 Yes
Hardware draytek vigor130 - No
Operating System draytek vigornic_132_firmware < 3.8.5.1 Yes
Hardware draytek vigornic_132 - No
Operating System draytek vigor3910_firmware < 4.3.2.2 Yes
Hardware draytek vigor3910 - No
Operating System draytek vigor3220_firmware < 3.9.7.4 Yes
Hardware draytek vigor3220 - No
Operating System draytek vigor2962_firmware < 4.3.2.2 Yes
Hardware draytek vigor2962 - No
Operating System draytek vigor2962p_firmware < 4.3.2.2 Yes
Hardware draytek vigor2962p - No
Operating System draytek vigor1000b_firmware < 4.3.2.2 Yes
Hardware draytek vigor1000b - No
Operating System draytek vigor2952_firmware < 3.9.7.4 Yes
Hardware draytek vigor2952 - No
Operating System draytek vigor2952p_firmware < 3.9.7.4 Yes
Hardware draytek vigor2952p - No
Operating System draytek vigor2927_firmware < 4.4.2.3 Yes
Hardware draytek vigor2927 - No
Operating System draytek vigor2927ax_firmware < 4.4.2.3 Yes
Hardware draytek vigor2927ax - No
Operating System draytek vigor2927ac_firmware < 4.4.2.3 Yes
Hardware draytek vigor2927ac - No
Operating System draytek vigor2927vac_firmware < 4.4.2.3 Yes
Hardware draytek vigor2927vac - No
Operating System draytek vigor2927f_firmware < 4.4.2.3 Yes
Hardware draytek vigor2927f - No
Operating System draytek vigor2927l_firmware < 4.4.2.3 Yes
Hardware draytek vigor2927l - No
Operating System draytek vigor2927lac_firmware < 4.4.2.3 Yes
Hardware draytek vigor2927lac - No
Operating System draytek vigor2926_firmware < 3.9.9.1 Yes
Hardware draytek vigor2926 - No
Operating System draytek vigor2926n_firmware < 3.9.9.1 Yes
Hardware draytek vigor2926n - No
Operating System draytek vigor2926ac_firmware < 3.9.9.1 Yes
Hardware draytek vigor2926ac - No
Operating System draytek vigor2926vac_firmware < 3.9.9.1 Yes
Hardware draytek vigor2926vac - No
Operating System draytek vigor2926l_firmware < 3.9.9.1 Yes
Hardware draytek vigor2926l - No
Operating System draytek vigor2926ln_firmware < 3.9.9.1 Yes
Hardware draytek vigor2926ln - No
Operating System draytek vigor2926lac_firmware < 3.9.9.1 Yes
Hardware draytek vigor2926lac - No
Operating System draytek vigor2925_firmware < 3.9.4 Yes
Hardware draytek vigor2925 - No
Operating System draytek vigor2925n_firmware < 3.9.4 Yes
Hardware draytek vigor2925n - No
Operating System draytek vigor2925n-plus_firmware < 3.9.4 Yes
Hardware draytek vigor2925n-plus - No
Operating System draytek vigor2925vn-plus_firmware < 3.9.4 Yes
Hardware draytek vigor2925vn-plus - No
Operating System draytek vigor2925ac_firmware < 3.9.4 Yes
Hardware draytek vigor2925ac - No
Operating System draytek vigor2925vac_firmware < 3.9.4 Yes
Hardware draytek vigor2925vac - No
Operating System draytek vigor2925fn_firmware < 3.9.4 Yes
Hardware draytek vigor2925fn - No
Operating System draytek vigor2925l_firmware < 3.9.4 Yes
Hardware draytek vigor2925l - No
Operating System draytek vigor2925ln_firmware < 3.9.4 Yes
Hardware draytek vigor2925ln - No
Operating System draytek vigor2915_firmware < 4.4.2.1 Yes
Hardware draytek vigor2915 - No
Operating System draytek vigor2915ac_firmware < 4.4.2.1 Yes
Hardware draytek vigor2915ac - No
Operating System draytek vigor2866_firmware < 4.4.1.1 Yes
Hardware draytek vigor2866 - No
Operating System draytek vigor2866ax_firmware < 4.4.1.1 Yes
Hardware draytek vigor2866ax - No
Operating System draytek vigor2866ac_firmware < 4.4.1.1 Yes
Hardware draytek vigor2866ac - No
Operating System draytek vigor2866vac_firmware < 4.4.1.1 Yes
Hardware draytek vigor2866vac - No
Operating System draytek vigor2866l_firmware < 4.4.1.1 Yes
Hardware draytek vigor2866l - No
Operating System draytek vigor2866lac_firmware < 4.4.1.1 Yes
Hardware draytek vigor2866lac - No
Operating System draytek vigor2865_firmware < 4.4.1.1 Yes
Hardware draytek vigor2865 - No
Operating System draytek vigor2865ax_firmware < 4.4.1.1 Yes
Hardware draytek vigor2865ax - No
Operating System draytek vigor2865ac_firmware < 4.4.1.1 Yes
Hardware draytek vigor2865ac - No
Operating System draytek vigor2865vac_firmware < 4.4.1.1 Yes
Hardware draytek vigor2865vac - No
Operating System draytek vigor2865l_firmware < 4.4.1.1 Yes
Hardware draytek vigor2865l - No
Operating System draytek vigor2865lac_firmware < 4.4.1.1 Yes
Hardware draytek vigor2865lac - No
Operating System draytek vigor2862_firmware < 3.9.9.1 Yes
Hardware draytek vigor2862 - No
Operating System draytek vigor2862n_firmware < 3.9.9.1 Yes
Hardware draytek vigor2862n - No
Operating System draytek vigor2862ac_firmware < 3.9.9.1 Yes
Hardware draytek vigor2862ac - No
Operating System draytek vigor2862vac_firmware < 3.9.9.1 Yes
Hardware draytek vigor2862vac - No
Operating System draytek vigor2862b_firmware < 3.9.9.1 Yes
Hardware draytek vigor2862b - No
Operating System draytek vigor2862bn_firmware < 3.9.9.1 Yes
Hardware draytek vigor2862bn - No
Operating System draytek vigor2862l_firmware < 3.9.9.1 Yes
Hardware draytek vigor2862l - No
Operating System draytek vigor2862ln_firmware < 3.9.9.1 Yes
Hardware draytek vigor2862ln - No
Operating System draytek vigor2862lac_firmware < 3.9.9.1 Yes
Hardware draytek vigor2862lac - No

References

How SecUtils Interprets This CVE

SecUtils normalizes and enriches National Vulnerability Database (NVD) records by standardizing vendor and product identifiers, aggregating vulnerability metadata from both NVD and MITRE sources, and providing structured context for security teams. For draytek's affected products, we extract Common Platform Enumeration (CPE) data, Common Weakness Enumeration (CWE) classifications, CVSS severity metrics, and reference data to enable rapid vulnerability prioritization and asset correlation. This record contains no exploit code, proof-of-concept instructions, or attack methodologies—only defensive intelligence necessary for patch management, risk assessment, and security operations.