Vendor
Command Injection Vulnerability in DrayTek VigorSwitch
2 TTPs 1 CVEAuthenticated attackers can exploit a command injection flaw in the DrayTek VigorSwitch commandTable function to achieve root-level remote code execution.
Buffer Overflow Vulnerability in DrayTek VigorAP Devices
2 TTPs 1 CVEDrayTek VigorAP models contain a buffer overflow vulnerability in the setLan function, allowing remote attackers with administrative credentials to trigger denial of service or arbitrary code execution.
Critical OS Command Injection in DrayTek VigorSwitch
1 rule 3 TTPs 1 CVEMultiple DrayTek VigorSwitch models contain a pre-authentication command injection vulnerability (CVE-2026-71921) in the setget.cgi interface that allows unauthenticated remote attackers to execute arbitrary commands as root.
Remote Command Injection in DrayTek VigorAP dray_apm Component
2 TTPs 1 CVEMultiple DrayTek VigorAP models are vulnerable to pre-authentication remote command injection due to insufficient UDP input validation in the dray_apm component.
DrayTek Vigor 2960 Unauthenticated Remote Command Execution via CVE-2022-50994
2 rules 1 TTP 1 CVEDrayTek Vigor 2960 firmware versions prior to 1.5.1.4 are vulnerable to OS command injection (CVE-2022-50994) in the CGI login handler, allowing unauthenticated remote attackers to execute arbitrary commands by injecting shell metacharacters into the formpassword parameter if the target account has MOTP enabled.