Command Injection Vulnerability in DrayTek VigorSwitch Series
CVE-2026-71916

8.6HIGH

What is CVE-2026-71916?

Multiple models of the DrayTek VigorSwitch have been found to contain a command injection vulnerability within the commandTable function. This issue arises from insufficient filtering of potentially malicious characters, such as backticks, newline characters, and single quotes, within the parameter field. A remote attacker, having valid administrative credentials, could exploit this vulnerability by sending specially crafted input that allows them to execute arbitrary commands with root privileges on the affected device. This situation presents a significant risk as it can lead to unauthorized access and control over network operations.

Affected Version(s)

VigorSwitch FX2120 0 < 3.9.10

VigorSwitch G1280 0 < 2.9.10

VigorSwitch G1282 0 < 2.9.10

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jincheng Wang (@winmt)
Le Yu (Nanjing University of Posts and Telecommunications)
Xiapu Luo (The Hong Kong Polytechnic University)
.