VYPR

VigorAP

by Draytek

CVEs (11)

  • CVE-2026-71914CriAug 24, 2026
    risk 0.64cvss 9.8epss

    Multiple DrayTek VigorAP models contain a command injection vulnerability in the dray_apm component. The vulnerability is caused by insufficient validation of UDP message content after START_SPEED_TEST before command execution. A remote attacker can trigger this vulnerability…

  • CVE-2026-71913HigAug 24, 2026
    risk 0.47cvss 7.2epss

    Multiple DrayTek VigorAP models contain a command injection vulnerability in the upload_settings.cgi interface. The vulnerability is caused by insufficient filtering before the restorekey field is concatenated into a shell command. A remote attacker can trigger this…

  • CVE-2026-71912HigAug 24, 2026
    risk 0.47cvss 7.2epss

    Multiple DrayTek VigorAP models contain a buffer overflow vulnerability in the apautotest function. The vulnerability is caused by missing length checks during memory copy operations involving the CMD6 field. A remote attacker can trigger this vulnerability via crafted input,…

  • CVE-2026-71911HigAug 24, 2026
    risk 0.47cvss 7.2epss

    Multiple DrayTek VigorAP models contain a buffer overflow vulnerability in the setLan function. The vulnerability is caused by missing length checks during memory copy operations involving the lanVlanId0, lanIp, and lanNetmask fields. A remote attacker can trigger this…

  • CVE-2026-71910HigAug 24, 2026
    risk 0.47cvss 7.2epss

    Multiple DrayTek VigorAP models contain a command injection vulnerability in the apautotest function. The vulnerability is caused by insufficient validation of the CMD0, CMD3, and CMD6 fields before command execution. A remote attacker can trigger this vulnerability via crafted…

  • CVE-2026-71909HigAug 24, 2026
    risk 0.47cvss 7.2epss

    Multiple DrayTek VigorAP models contain a command injection vulnerability in the InquierTime function. The vulnerability is caused by insufficient filtering of the time field before command execution. A remote attacker can trigger this vulnerability via crafted input to execute…

  • CVE-2026-71908HigAug 24, 2026
    risk 0.47cvss 7.2epss

    Multiple DrayTek VigorAP models contain a command injection vulnerability in the mesh_start_speed_test function. The vulnerability is caused by insufficient sanitization of the meshdevice_index and meshdevice_ip fields before command execution. A remote attacker can trigger this…

  • CVE-2026-71907HigAug 24, 2026
    risk 0.47cvss 7.2epss

    Multiple DrayTek VigorAP models contain a command injection vulnerability in the setcamset function. The vulnerability is caused by insufficient filtering of the selectSlaves field before command execution. A remote attacker can trigger this vulnerability via crafted input to…

  • CVE-2026-71906HigAug 24, 2026
    risk 0.47cvss 7.2epss

    Multiple DrayTek VigorAP models contain a command injection vulnerability in the setLan function. The vulnerability is caused by insufficient validation of the lanIp and lanNetmask fields before command execution. A remote attacker can trigger this vulnerability via crafted…

  • CVE-2026-71905HigAug 24, 2026
    risk 0.47cvss 7.2epss

    Multiple DrayTek VigorAP models contain a command injection vulnerability in the ExportSettings function. The vulnerability is caused by insufficient filtering of the backupkey, backuptype, and realtime fields before command execution. A remote attacker can trigger this…

  • CVE-2026-71904HigAug 24, 2026
    risk 0.47cvss 7.2epss

    Multiple DrayTek VigorAP models contain a command injection vulnerability in the tr069TestInform function. The vulnerability is caused by insufficient filtering of dangerous characters before the event_code field is concatenated into a system command. A remote attacker can…