Buffer Overflow Vulnerability in DrayTek VigorSwitch
CVE-2026-71937
Key Information:
- Vendor
Draytek Corporation
- Vendor
- CVE Published:
- 24 August 2026
What is CVE-2026-71937?
DrayTek VigorSwitch devices are susceptible to a buffer overflow vulnerability within the poe_schedule_profile function. This issue stems from inadequate handling of input data, specifically due to the repetitive concatenation of fields such as start_date, start_time, and more, into fixed-size buffers without appropriate length validation. A remote attacker with administrative credentials can exploit this vulnerability through specially crafted input, potentially leading to a denial of service condition or the execution of arbitrary commands. It is essential for users to apply the necessary patches and monitor their devices.
Affected Version(s)
VigorSwitch FX2120 0 < 3.9.10
VigorSwitch G1280 0 < 2.9.10
VigorSwitch G1282 0 < 2.9.10
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
