DrayTek Vigor3910 devices through 4.3.2.6 are vulnerable to reflected XSS by authenticated users, caused by missing validation of the sFormAuthStr parameter.
https://www.forescout.com/resources/draybreak-draytek-research/
https://www.forescout.com/resources/draytek14-vulnerabilities