<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>VigorAP - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/vigorap/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 24 Aug 2026 20:03:34 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/vigorap/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Buffer Overflow Vulnerability in DrayTek VigorAP Devices</title><link>https://feed.craftedsignal.io/briefs/2026-08-draytek-buffer-overflow/</link><pubDate>Mon, 24 Aug 2026 20:03:34 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-draytek-buffer-overflow/</guid><description>DrayTek VigorAP models contain a buffer overflow vulnerability in the setLan function, allowing remote attackers with administrative credentials to trigger denial of service or arbitrary code execution.</description><content:encoded><![CDATA[<p>DrayTek VigorAP models are susceptible to a buffer overflow vulnerability (CVE-2026-71911) located within the setLan function of the device's web management interface. This issue arises from improper validation of length constraints when processing memory copy operations for the lanVlanId0, lanIp, and lanNetmask parameters.</p>
<p>An attacker who has obtained valid administrative credentials for the web interface can supply specially crafted inputs to these fields. By exceeding the expected buffer size, the attacker can cause the service to crash, resulting in a denial-of-service (DoS) condition, or potentially achieve arbitrary command execution on the target device. This vulnerability highlights the importance of restricting access to administrative interfaces and monitoring for anomalous configurations on edge networking equipment.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability could lead to a complete compromise of the affected DrayTek VigorAP units, allowing attackers to persist within the network environment or disable critical wireless infrastructure. The vulnerability affects multiple VigorAP models globally. The requirement for administrative credentials limits the attack surface to those who have already gained unauthorized access to management accounts, but significantly escalates the impact of such access.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Monitor web management interface logs for repeated or unusually formatted POST requests to the setLan function.</li>
<li>Audit administrative account access and enforce multi-factor authentication (MFA) to mitigate the risk of credential theft required for exploitation.</li>
<li>Check the official DrayTek support portal for firmware updates addressing CVE-2026-71911 and apply them to all exposed VigorAP devices.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>