VYPR

VigorSwitch

by Draytek

CVEs (29)

  • CVE-2026-71924HigAug 24, 2026
    risk 0.47cvss 7.2epss

    Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the getVid function. The vulnerability is caused by insufficient filtering of the username and password fields before command execution. A remote attacker can trigger this vulnerability via crafted…

  • CVE-2026-71923HigAug 24, 2026
    risk 0.47cvss 7.2epss

    Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the auth_set function. The vulnerability is caused by insufficient filtering of the username and password fields before command execution. A remote attacker can trigger this vulnerability via…

  • CVE-2026-71919HigAug 24, 2026
    risk 0.47cvss 7.2epss

    Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the sysreboot function. The vulnerability is caused by insufficient filtering of the config, act, pathN, and valueN fields before command execution. A remote attacker can trigger this vulnerability…

  • CVE-2026-71918HigAug 24, 2026
    risk 0.47cvss 7.2epss

    Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the webBackupAction function. The vulnerability is caused by insufficient filtering of the option, key, pw_encode, pathN, and valueN fields before command execution. A remote attacker can trigger…

  • CVE-2026-71917HigAug 24, 2026
    risk 0.47cvss 7.2epss

    Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the pingtrace function. The vulnerability is caused by insufficient validation of the host field before command execution. A remote attacker can trigger this vulnerability via crafted input to…

  • CVE-2026-71916HigAug 24, 2026
    risk 0.47cvss 7.2epss

    Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the commandTable function. The vulnerability is caused by incomplete filtering of dangerous characters such as backticks, newline characters, and single quotes in the parameter field. A remote…

  • CVE-2026-71915HigAug 24, 2026
    risk 0.47cvss 7.2epss

    Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the jsonstatus function. The vulnerability is caused by insufficient filtering of the usescript, usefile, and option fields before command execution. A remote attacker can trigger this vulnerability…

  • CVE-2026-71932MedAug 24, 2026
    risk 0.32cvss 4.9epss

    Multiple DrayTek VigorSwitch models contain a directory traversal vulnerability in the getSyslogFile function. The vulnerability is caused by insufficient validation of the option field. A remote attacker can trigger this vulnerability via crafted input containing path traversal…

  • CVE-2026-71920MedAug 24, 2026
    risk 0.32cvss 4.9epss

    Multiple DrayTek VigorSwitch models contain a null pointer dereference vulnerability in the formlogout function. The vulnerability is caused by missing checks for an empty or absent Cookie header before string handling. A remote attacker can trigger this vulnerability via a…

Page 2 of 2