<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>DrayTek Corporation - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/vendors/draytek-corporation/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 24 Aug 2026 20:02:56 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/vendors/draytek-corporation/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Critical OS Command Injection in DrayTek VigorSwitch</title><link>https://feed.craftedsignal.io/briefs/2026-08-draytek-cmd-injection/</link><pubDate>Mon, 24 Aug 2026 20:02:56 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-draytek-cmd-injection/</guid><description>Multiple DrayTek VigorSwitch models contain a pre-authentication command injection vulnerability (CVE-2026-71921) in the setget.cgi interface that allows unauthenticated remote attackers to execute arbitrary commands as root.</description><content:encoded><![CDATA[<p>DrayTek has disclosed a critical command injection vulnerability, identified as CVE-2026-71921, affecting multiple models within the VigorSwitch series. The vulnerability is located in the setget.cgi interface, which fails to properly sanitize the 'pass' parameter before passing it to an underlying system process. An unauthenticated remote attacker can exploit this flaw by sending a crafted HTTP request containing shell metacharacters, leading to arbitrary command execution with root-level privileges on the affected networking equipment. Given that these devices often operate at the perimeter or core of internal networks, successful exploitation grants the attacker persistent control over the network infrastructure. Defenders should prioritize updating firmware for all affected VigorSwitch units listed below.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of CVE-2026-71921 results in complete system compromise, allowing an attacker to gain root access to the affected switch. This facilitates unauthorized network traffic interception, pivoting into internal network segments, or the installation of persistent backdoors on the device. Numerous models are impacted, spanning various firmware versions, creating a widespread exposure for organizations utilizing DrayTek infrastructure.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Immediately update firmware on all affected DrayTek VigorSwitch models to the non-vulnerable versions specified in the vendor security advisory.</li>
<li>Apply access control lists (ACLs) to restrict management interface access (setget.cgi) to trusted internal management subnets only.</li>
<li>Deploy the Sigma rule provided below to identify exploitation attempts targeting the setget.cgi interface via web logs.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>vulnerability</category><category>remote-code-execution</category><category>network-infrastructure</category><category>cve</category><category>network-security</category><category>network</category><category>hardware</category></item></channel></rss>