{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/vigorap-906/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-71914"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["VigorAP 918R","VigorAP 960C","VigorAP 1060C","VigorAP 906","VigorAP 912C","VigorAP 903"],"_cs_severities":["critical"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["DrayTek"],"content_html":"\u003cp\u003eDrayTek has disclosed a critical remote code execution vulnerability (CVE-2026-71914) affecting multiple VigorAP access point models. The vulnerability resides within the dray_apm component, which is responsible for device management and speed testing functionality. An unauthenticated remote attacker can exploit this flaw by sending a crafted UDP packet to the device. Specifically, the dray_apm component fails to properly validate the content of UDP messages sent after a START_SPEED_TEST command is issued. This lack of validation allows an attacker to inject and execute arbitrary commands with root-level privileges on the underlying operating system. Given the nature of these devices as network infrastructure, successful exploitation allows full control over the access point, potentially enabling further lateral movement within the network or man-in-the-middle attacks on connected wireless clients.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs network reconnaissance to identify reachable DrayTek VigorAP management interfaces or specific UDP ports associated with the dray_apm component.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious UDP packet containing a payload designed to trigger the dray_apm speed test sequence.\u003c/li\u003e\n\u003cli\u003eAttacker appends command injection characters or malicious shell syntax to the payload following the START_SPEED_TEST identifier.\u003c/li\u003e\n\u003cli\u003eAttacker transmits the crafted UDP packet to the target VigorAP device.\u003c/li\u003e\n\u003cli\u003eThe dray_apm component on the target device receives and processes the UDP message.\u003c/li\u003e\n\u003cli\u003eInsufficient input validation leads the device to parse the malicious content as part of an OS command.\u003c/li\u003e\n\u003cli\u003eThe device executes the injected payload with root privileges.\u003c/li\u003e\n\u003cli\u003eAttacker gains persistent access or initiates further exfiltration/lateral movement from the compromised access point.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in full root-level compromise of the affected DrayTek VigorAP access points. This grants an attacker complete control over network traffic flowing through the device, potentially facilitating data interception, redirection, or unauthorized access to the internal network. Affected models include the VigorAP 918R, 960C, 1060C, 906, 912C, and 903. Customers should prioritize firmware updates immediately to mitigate this critical risk.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eApply the official vendor firmware updates provided by DrayTek to all affected VigorAP models to remediate CVE-2026-71914.\u003c/li\u003e\n\u003cli\u003eRestrict access to the management and speed test ports of VigorAP devices to trusted administrative IP addresses using firewall rules or ACLs to prevent unauthenticated remote access.\u003c/li\u003e\n\u003cli\u003eMonitor network traffic for unusual UDP patterns directed at DrayTek devices, specifically identifying high-frequency or anomalous UDP packets involving the dray_apm service.\u003c/li\u003e\n\u003cli\u003eConduct a security audit of network edge infrastructure to identify vulnerable VigorAP firmware versions identified in the affected products list.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-24T20:02:45Z","date_published":"2026-08-24T20:02:45Z","id":"https://feed.craftedsignal.io/briefs/2026-08-draytek-rce/","summary":"Multiple DrayTek VigorAP models are vulnerable to pre-authentication remote command injection due to insufficient UDP input validation in the dray_apm component.","title":"Remote Command Injection in DrayTek VigorAP dray_apm Component","url":"https://feed.craftedsignal.io/briefs/2026-08-draytek-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - VigorAP 906","version":"https://jsonfeed.org/version/1.1"}