Skip to content
Threat Feed

Vendor

DrayTek

5 briefs RSS
high advisory

Command Injection Vulnerability in DrayTek VigorSwitch

Authenticated attackers can exploit a command injection flaw in the DrayTek VigorSwitch commandTable function to achieve root-level remote code execution.

VigorSwitch vulnerability remote-code-execution network-infrastructure
2t 1c
high advisory

Buffer Overflow Vulnerability in DrayTek VigorAP Devices

DrayTek VigorAP models contain a buffer overflow vulnerability in the setLan function, allowing remote attackers with administrative credentials to trigger denial of service or arbitrary code execution.

VigorAP
2t 1c
critical advisory

Critical OS Command Injection in DrayTek VigorSwitch

Multiple DrayTek VigorSwitch models contain a pre-authentication command injection vulnerability (CVE-2026-71921) in the setget.cgi interface that allows unauthenticated remote attackers to execute arbitrary commands as root.

VigorSwitch G2540xs +10 vulnerability remote-code-execution network-infrastructure cve network-security network hardware
1r 3t 1c
critical advisory

Remote Command Injection in DrayTek VigorAP dray_apm Component

Multiple DrayTek VigorAP models are vulnerable to pre-authentication remote command injection due to insufficient UDP input validation in the dray_apm component.

VigorAP 918R +5
2t 1c
high advisory

DrayTek Vigor 2960 Unauthenticated Remote Command Execution via CVE-2022-50994

DrayTek Vigor 2960 firmware versions prior to 1.5.1.4 are vulnerable to OS command injection (CVE-2022-50994) in the CGI login handler, allowing unauthenticated remote attackers to execute arbitrary commands by injecting shell metacharacters into the formpassword parameter if the target account has MOTP enabled.

Vigor 2960 firmware cve command injection rce network device
2r 1t 1c