CVE-2024-41591

CVSS 3.1 Score 6.1 of 10 (medium)

Details

Published Oct 3, 2024
Updated: Mar 14, 2025
CWE ID 79

Summary

CVE-2024-41591 is a newly discovered vulnerability affecting DrayTek Vigor3910 devices up to version 4.3.2.6. This issue permits unauthenticated attackers to carry out Domain Name System (DNS) reflected Cross-Site Scripting (XSS) attacks. The vulnerability exists due to insufficient input validation on certain web pages, leading to the reflection of malicious scripts when a user visits a specially crafted website. Successful exploitation could result in the theft of user session cookies or other sensitive information, as well as the execution of arbitrary malicious code within the user's browser session. Users are strongly advised to update their DrayTek Vigor3910 devices to the latest available firmware version as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • DrayTek Vigor 3910

Affected Vendors

  • DrayTek