Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setDevNet function. The vulnerability is caused by insufficient filtering of the username and password fields before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administrative credentials for the device's web management interface.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 24 Aug 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setDevNet function. The vulnerability is caused by insufficient filtering of the username and password fields before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administrative credentials for the device's web management interface. | |
| Title | DrayTek VigorSwitch Multiple Models OS Command Injection via setDevNet | |
| First Time appeared |
Draytek
Draytek vigorswitch Fx2120 Firmware Draytek vigorswitch G1282 Firmware Draytek vigorswitch G2100 Firmware Draytek vigorswitch G2121 Firmware Draytek vigorswitch G2280x Firmware Draytek vigorswitch G2540xs Firmware Draytek vigorswitch P1282 Firmware Draytek vigorswitch P2100 Firmware Draytek vigorswitch P2280x Firmware Draytek vigorswitch P2540xs Firmware Draytek vigorswitch Pq2121x Firmware Draytek vigorswitch Pq2200xb Firmware Draytek vigorswitch Q2121x Firmware Draytek vigorswitch Q2200x Firmware |
|
| Weaknesses | CWE-78 | |
| CPEs | cpe:2.3:o:draytek:vigorswitch_fx2120_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:draytek:vigorswitch_g1282_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:draytek:vigorswitch_g2100_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:draytek:vigorswitch_g2121_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:draytek:vigorswitch_g2280x_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:draytek:vigorswitch_g2540xs_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:draytek:vigorswitch_p1282_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:draytek:vigorswitch_p2100_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:draytek:vigorswitch_p2280x_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:draytek:vigorswitch_p2540xs_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:draytek:vigorswitch_pq2121x_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:draytek:vigorswitch_pq2200xb_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:draytek:vigorswitch_q2121x_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:draytek:vigorswitch_q2200x_firmware:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Draytek
Draytek vigorswitch Fx2120 Firmware Draytek vigorswitch G1282 Firmware Draytek vigorswitch G2100 Firmware Draytek vigorswitch G2121 Firmware Draytek vigorswitch G2280x Firmware Draytek vigorswitch G2540xs Firmware Draytek vigorswitch P1282 Firmware Draytek vigorswitch P2100 Firmware Draytek vigorswitch P2280x Firmware Draytek vigorswitch P2540xs Firmware Draytek vigorswitch Pq2121x Firmware Draytek vigorswitch Pq2200xb Firmware Draytek vigorswitch Q2121x Firmware Draytek vigorswitch Q2200x Firmware |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-24T17:08:06.077Z
Reserved: 2026-08-08T16:43:04.176Z
Link: CVE-2026-71943
No data.
Status : Received
Published: 2026-08-24T18:17:20.077
Modified: 2026-08-24T18:17:20.077
Link: CVE-2026-71943
No data.
OpenCVE Enrichment
Updated: 2026-08-24T19:15:04Z
Weaknesses