On DrayTek Vigor2925 devices with firmware 3.8.4.3, Incorrect Access Control exists in loginset.htm, and can be used to trigger XSS. NOTE: this is an end-of-life product.Referenceshttps://www.facebook.com/Huang.YuHsiang.Phone/posts/1815316691945755https://www.draytek.com/about/security-advisory/urgent-security-updates-to-draytek-routers