Command Injection Vulnerability in DrayTek VigorSwitch Series
CVE-2026-71916
Key Information:
- Vendor
Draytek Corporation
- Vendor
- CVE Published:
- 24 August 2026
What is CVE-2026-71916?
Multiple models of the DrayTek VigorSwitch have been found to contain a command injection vulnerability within the commandTable function. This issue arises from insufficient filtering of potentially malicious characters, such as backticks, newline characters, and single quotes, within the parameter field. A remote attacker, having valid administrative credentials, could exploit this vulnerability by sending specially crafted input that allows them to execute arbitrary commands with root privileges on the affected device. This situation presents a significant risk as it can lead to unauthorized access and control over network operations.
Affected Version(s)
VigorSwitch FX2120 0 < 3.9.10
VigorSwitch G1280 0 < 2.9.10
VigorSwitch G1282 0 < 2.9.10
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
