VulnerabilityModified
CVE-2013-5703
The DrayTek Vigor 2700 router 2.8.3 allows remote attackers to execute arbitrary JavaScript code, and modify settings or the DNS cache, via a crafted SSID value that is not properly handled during insertion into the sWlessSurvey value in variables.js.
MEDIUM 6.8EPSS 1.26%
Does this matter?
Lower severity and a low EPSS score (1.26%). Track it; it rarely justifies an emergency change on its own.
Description
The DrayTek Vigor 2700 router 2.8.3 allows remote attackers to execute arbitrary JavaScript code, and modify settings or the DNS cache, via a crafted SSID value that is not properly handled during insertion into the sWlessSurvey value in variables.js.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 1.26% probability · 68th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-78
- Affected
- draytek/vigor 2700 router firmware · draytek/vigor 2700 router
- Source
- cve@mitre.org
References
- http://www.kb.cert.org/vuls/id/101462US Government Resource
- http://www.kb.cert.org/vuls/id/101462US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.