Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The DrayTek Vigor 2700 router 2.8.3 allows remote attackers to execute arbitrary JavaScript code, and modify settings or the DNS cache, via a crafted SSID value that is not properly handled during insertion into the sWlessSurvey value in variables.js.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
DrayTek Vigor 2700 远程命令注入漏洞
Vulnerability Description
DrayTek Vigor 2700是居易科技(DrayTek)公司的一款带有防火墙功能的无线路由器产品。 DrayTek Vigor 2700路由器2.8.3版本中存在命令注入漏洞,该漏洞源于在variables.js列表中的sWlessSurvey变量没有正确添加SSID值。远程攻击者可通过特制的SSID值利用该漏洞执行任意JavaScript代码,修改设置或DNS缓存。
CVSS Information
N/A
Vulnerability Type
N/A