Buffer Overflow Vulnerability in DrayTek VigorSwitch Products
CVE-2026-71935
Key Information:
- Vendor
Draytek Corporation
- Vendor
- CVE Published:
- 24 August 2026
What is CVE-2026-71935?
Multiple models of DrayTek VigorSwitch have a vulnerability within the webBackupAction function, triggered by inadequate handling of input data. Specifically, the issue arises due to repeated concatenation of various input fields into fixed-size buffers without proper length validation. This oversight allows a remote attacker with valid administrative access to craft malicious inputs that can lead to a denial of service or potentially execute arbitrary commands on the device. Addressing this issue promptly is essential for maintaining the security of network infrastructures utilizing VigorSwitch devices.
Affected Version(s)
VigorSwitch FX2120 0 < 3.9.10
VigorSwitch G1280 0 < 2.9.10
VigorSwitch G1282 0 < 2.9.10
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
