{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/vigorswitch-g2542x/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-71921"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["VigorSwitch G2540xs","VigorSwitch P2540xs","VigorSwitch FX2120","VigorSwitch G2282x","VigorSwitch P2282x","VigorSwitch Q2300x","VigorSwitch PQ2300xb","VigorSwitch G2542x","VigorSwitch P2542x","VigorSwitch P2542xh","VigorSwitch PX2060"],"_cs_severities":["critical"],"_cs_tags":["vulnerability","remote-code-execution","network-infrastructure","cve","network-security","network","hardware"],"_cs_type":"advisory","_cs_vendors":["DrayTek","DrayTek Corporation"],"content_html":"\u003cp\u003eDrayTek has disclosed a critical command injection vulnerability, identified as CVE-2026-71921, affecting multiple models within the VigorSwitch series. The vulnerability is located in the setget.cgi interface, which fails to properly sanitize the 'pass' parameter before passing it to an underlying system process. An unauthenticated remote attacker can exploit this flaw by sending a crafted HTTP request containing shell metacharacters, leading to arbitrary command execution with root-level privileges on the affected networking equipment. Given that these devices often operate at the perimeter or core of internal networks, successful exploitation grants the attacker persistent control over the network infrastructure. Defenders should prioritize updating firmware for all affected VigorSwitch units listed below.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-71921 results in complete system compromise, allowing an attacker to gain root access to the affected switch. This facilitates unauthorized network traffic interception, pivoting into internal network segments, or the installation of persistent backdoors on the device. Numerous models are impacted, spanning various firmware versions, creating a widespread exposure for organizations utilizing DrayTek infrastructure.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately update firmware on all affected DrayTek VigorSwitch models to the non-vulnerable versions specified in the vendor security advisory.\u003c/li\u003e\n\u003cli\u003eApply access control lists (ACLs) to restrict management interface access (setget.cgi) to trusted internal management subnets only.\u003c/li\u003e\n\u003cli\u003eDeploy the Sigma rule provided below to identify exploitation attempts targeting the setget.cgi interface via web logs.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-24T20:04:30Z","date_published":"2026-08-24T20:02:56Z","id":"https://feed.craftedsignal.io/briefs/2026-08-draytek-cmd-injection/","summary":"Multiple DrayTek VigorSwitch models contain a pre-authentication command injection vulnerability (CVE-2026-71921) in the setget.cgi interface that allows unauthenticated remote attackers to execute arbitrary commands as root.","title":"Critical OS Command Injection in DrayTek VigorSwitch","url":"https://feed.craftedsignal.io/briefs/2026-08-draytek-cmd-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - VigorSwitch G2542x","version":"https://jsonfeed.org/version/1.1"}