CVE-2013-5703: DrayTek Vigor 2700 Router

Medium severity, CVSS 6.8. EPSS: 1.3% chance of exploitation in the next 30 days.

The DrayTek Vigor 2700 router 2.8.3 allows remote attackers to execute arbitrary JavaScript code, and modify settings or the DNS cache, via a crafted SSID value that is not properly handled during insertion into the sWlessSurvey value in variables.js.

Affected products

  • DrayTek Vigor 2700 Router
  • DrayTek Vigor 2700 Router Firmware: version 2.8.3 only

Published 2013-10-22. Last modified 2026-06-16.