<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>VigorAP 1060C - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/vigorap-1060c/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 24 Aug 2026 20:02:45 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/vigorap-1060c/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Remote Command Injection in DrayTek VigorAP dray_apm Component</title><link>https://feed.craftedsignal.io/briefs/2026-08-draytek-rce/</link><pubDate>Mon, 24 Aug 2026 20:02:45 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-draytek-rce/</guid><description>Multiple DrayTek VigorAP models are vulnerable to pre-authentication remote command injection due to insufficient UDP input validation in the dray_apm component.</description><content:encoded><![CDATA[<p>DrayTek has disclosed a critical remote code execution vulnerability (CVE-2026-71914) affecting multiple VigorAP access point models. The vulnerability resides within the dray_apm component, which is responsible for device management and speed testing functionality. An unauthenticated remote attacker can exploit this flaw by sending a crafted UDP packet to the device. Specifically, the dray_apm component fails to properly validate the content of UDP messages sent after a START_SPEED_TEST command is issued. This lack of validation allows an attacker to inject and execute arbitrary commands with root-level privileges on the underlying operating system. Given the nature of these devices as network infrastructure, successful exploitation allows full control over the access point, potentially enabling further lateral movement within the network or man-in-the-middle attacks on connected wireless clients.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker performs network reconnaissance to identify reachable DrayTek VigorAP management interfaces or specific UDP ports associated with the dray_apm component.</li>
<li>Attacker crafts a malicious UDP packet containing a payload designed to trigger the dray_apm speed test sequence.</li>
<li>Attacker appends command injection characters or malicious shell syntax to the payload following the START_SPEED_TEST identifier.</li>
<li>Attacker transmits the crafted UDP packet to the target VigorAP device.</li>
<li>The dray_apm component on the target device receives and processes the UDP message.</li>
<li>Insufficient input validation leads the device to parse the malicious content as part of an OS command.</li>
<li>The device executes the injected payload with root privileges.</li>
<li>Attacker gains persistent access or initiates further exfiltration/lateral movement from the compromised access point.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation results in full root-level compromise of the affected DrayTek VigorAP access points. This grants an attacker complete control over network traffic flowing through the device, potentially facilitating data interception, redirection, or unauthorized access to the internal network. Affected models include the VigorAP 918R, 960C, 1060C, 906, 912C, and 903. Customers should prioritize firmware updates immediately to mitigate this critical risk.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Apply the official vendor firmware updates provided by DrayTek to all affected VigorAP models to remediate CVE-2026-71914.</li>
<li>Restrict access to the management and speed test ports of VigorAP devices to trusted administrative IP addresses using firewall rules or ACLs to prevent unauthenticated remote access.</li>
<li>Monitor network traffic for unusual UDP patterns directed at DrayTek devices, specifically identifying high-frequency or anomalous UDP packets involving the dray_apm service.</li>
<li>Conduct a security audit of network edge infrastructure to identify vulnerable VigorAP firmware versions identified in the affected products list.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category></item></channel></rss>