Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 24 Aug 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 24 Aug 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the jsonstatus function. The vulnerability is caused by insufficient filtering of the usescript, usefile, and option fields before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administrative credentials for the device's web management interface. | |
| Title | DrayTek VigorSwitch Multiple Models OS Command Injection via jsonstatus | |
| First Time appeared |
Draytek
Draytek vigorswitch Fx2120 Firmware Draytek vigorswitch G1282 Firmware Draytek vigorswitch G2100 Firmware Draytek vigorswitch G2121 Firmware Draytek vigorswitch G2280x Firmware Draytek vigorswitch G2540xs Firmware Draytek vigorswitch P1282 Firmware Draytek vigorswitch P2100 Firmware Draytek vigorswitch P2280x Firmware Draytek vigorswitch P2540xs Firmware Draytek vigorswitch Pq2121x Firmware Draytek vigorswitch Pq2200xb Firmware Draytek vigorswitch Q2121x Firmware Draytek vigorswitch Q2200x Firmware |
|
| Weaknesses | CWE-78 | |
| CPEs | cpe:2.3:o:draytek:vigorswitch_fx2120_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:draytek:vigorswitch_g1282_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:draytek:vigorswitch_g2100_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:draytek:vigorswitch_g2121_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:draytek:vigorswitch_g2280x_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:draytek:vigorswitch_g2540xs_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:draytek:vigorswitch_p1282_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:draytek:vigorswitch_p2100_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:draytek:vigorswitch_p2280x_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:draytek:vigorswitch_p2540xs_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:draytek:vigorswitch_pq2121x_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:draytek:vigorswitch_pq2200xb_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:draytek:vigorswitch_q2121x_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:draytek:vigorswitch_q2200x_firmware:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Draytek
Draytek vigorswitch Fx2120 Firmware Draytek vigorswitch G1282 Firmware Draytek vigorswitch G2100 Firmware Draytek vigorswitch G2121 Firmware Draytek vigorswitch G2280x Firmware Draytek vigorswitch G2540xs Firmware Draytek vigorswitch P1282 Firmware Draytek vigorswitch P2100 Firmware Draytek vigorswitch P2280x Firmware Draytek vigorswitch P2540xs Firmware Draytek vigorswitch Pq2121x Firmware Draytek vigorswitch Pq2200xb Firmware Draytek vigorswitch Q2121x Firmware Draytek vigorswitch Q2200x Firmware |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-24T19:04:44.763Z
Reserved: 2026-08-08T16:37:44.517Z
Link: CVE-2026-71915
Updated: 2026-08-24T19:04:41.500Z
Status : Received
Published: 2026-08-24T18:17:03.670
Modified: 2026-08-24T19:16:52.560
Link: CVE-2026-71915
No data.
OpenCVE Enrichment
Updated: 2026-08-24T19:45:03Z