cve/2024/CVE-2024-41584.md
2025-09-29 21:09:30 +02:00

735 B

CVE-2024-41584

Description

DrayTek Vigor3910 devices through 4.3.2.6 are vulnerable to reflected XSS by authenticated users, caused by missing validation of the sFormAuthStr parameter.

POC

Reference

Github

No PoCs found on GitHub currently.