DrayTek Vigor310 devices through 4.3.2.6 use unencrypted HTTP for authentication requests.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Link | Tags |
---|---|
https://www.forescout.com/resources/draytek14-vulnerabilities | broken link |
https://www.forescout.com/resources/draybreak-draytek-research/ | third party advisory |