{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/vigorap/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-71911"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["VigorAP"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["DrayTek"],"content_html":"\u003cp\u003eDrayTek VigorAP models are susceptible to a buffer overflow vulnerability (CVE-2026-71911) located within the setLan function of the device's web management interface. This issue arises from improper validation of length constraints when processing memory copy operations for the lanVlanId0, lanIp, and lanNetmask parameters.\u003c/p\u003e\n\u003cp\u003eAn attacker who has obtained valid administrative credentials for the web interface can supply specially crafted inputs to these fields. By exceeding the expected buffer size, the attacker can cause the service to crash, resulting in a denial-of-service (DoS) condition, or potentially achieve arbitrary command execution on the target device. This vulnerability highlights the importance of restricting access to administrative interfaces and monitoring for anomalous configurations on edge networking equipment.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability could lead to a complete compromise of the affected DrayTek VigorAP units, allowing attackers to persist within the network environment or disable critical wireless infrastructure. The vulnerability affects multiple VigorAP models globally. The requirement for administrative credentials limits the attack surface to those who have already gained unauthorized access to management accounts, but significantly escalates the impact of such access.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMonitor web management interface logs for repeated or unusually formatted POST requests to the setLan function.\u003c/li\u003e\n\u003cli\u003eAudit administrative account access and enforce multi-factor authentication (MFA) to mitigate the risk of credential theft required for exploitation.\u003c/li\u003e\n\u003cli\u003eCheck the official DrayTek support portal for firmware updates addressing CVE-2026-71911 and apply them to all exposed VigorAP devices.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-24T20:03:34Z","date_published":"2026-08-24T20:03:34Z","id":"https://feed.craftedsignal.io/briefs/2026-08-draytek-buffer-overflow/","summary":"DrayTek VigorAP models contain a buffer overflow vulnerability in the setLan function, allowing remote attackers with administrative credentials to trigger denial of service or arbitrary code execution.","title":"Buffer Overflow Vulnerability in DrayTek VigorAP Devices","url":"https://feed.craftedsignal.io/briefs/2026-08-draytek-buffer-overflow/"}],"language":"en","title":"CraftedSignal Threat Feed - VigorAP","version":"https://jsonfeed.org/version/1.1"}