VYPR

Vendor CVEs

Draytek

All CVEs

180 total · sorted by risk
  • CVE-2026-71915HigAug 24, 2026
    risk 0.47cvss 7.2epss 0.02

    Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the jsonstatus function. The vulnerability is caused by insufficient filtering of the usescript, usefile, and option fields before command execution. A remote attacker can trigger this vulnerability…

  • CVE-2026-71913HigAug 24, 2026
    risk 0.47cvss 7.2epss 0.02

    Multiple DrayTek VigorAP models contain a command injection vulnerability in the upload_settings.cgi interface. The vulnerability is caused by insufficient filtering before the restorekey field is concatenated into a shell command. A remote attacker can trigger this…

  • CVE-2026-71912HigAug 24, 2026
    risk 0.47cvss 7.2epss 0.01

    Multiple DrayTek VigorAP models contain a buffer overflow vulnerability in the apautotest function. The vulnerability is caused by missing length checks during memory copy operations involving the CMD6 field. A remote attacker can trigger this vulnerability via crafted input,…

  • CVE-2026-71911HigAug 24, 2026
    risk 0.47cvss 7.2epss 0.01

    Multiple DrayTek VigorAP models contain a buffer overflow vulnerability in the setLan function. The vulnerability is caused by missing length checks during memory copy operations involving the lanVlanId0, lanIp, and lanNetmask fields. A remote attacker can trigger this…

  • CVE-2026-71910HigAug 24, 2026
    risk 0.47cvss 7.2epss 0.02

    Multiple DrayTek VigorAP models contain a command injection vulnerability in the apautotest function. The vulnerability is caused by insufficient validation of the CMD0, CMD3, and CMD6 fields before command execution. A remote attacker can trigger this vulnerability via crafted…

  • CVE-2026-71909HigAug 24, 2026
    risk 0.47cvss 7.2epss 0.02

    Multiple DrayTek VigorAP models contain a command injection vulnerability in the InquierTime function. The vulnerability is caused by insufficient filtering of the time field before command execution. A remote attacker can trigger this vulnerability via crafted input to execute…

  • CVE-2026-71908HigAug 24, 2026
    risk 0.47cvss 7.2epss 0.02

    Multiple DrayTek VigorAP models contain a command injection vulnerability in the mesh_start_speed_test function. The vulnerability is caused by insufficient sanitization of the meshdevice_index and meshdevice_ip fields before command execution. A remote attacker can trigger this…

  • CVE-2026-71907HigAug 24, 2026
    risk 0.47cvss 7.2epss 0.02

    Multiple DrayTek VigorAP models contain a command injection vulnerability in the setcamset function. The vulnerability is caused by insufficient filtering of the selectSlaves field before command execution. A remote attacker can trigger this vulnerability via crafted input to…

  • CVE-2026-71906HigAug 24, 2026
    risk 0.47cvss 7.2epss 0.02

    Multiple DrayTek VigorAP models contain a command injection vulnerability in the setLan function. The vulnerability is caused by insufficient validation of the lanIp and lanNetmask fields before command execution. A remote attacker can trigger this vulnerability via crafted…

  • CVE-2026-71904HigAug 24, 2026
    risk 0.47cvss 7.2epss 0.02

    Multiple DrayTek VigorAP models contain a command injection vulnerability in the tr069TestInform function. The vulnerability is caused by insufficient filtering of dangerous characters before the event_code field is concatenated into a system command. A remote attacker can…

  • CVE-2024-41585MedOct 3, 2024
    risk 0.44cvss 6.8epss 0.01

    DrayTek Vigor3910 devices through 4.3.2.6 are affected by an OS command injection vulnerability that allows an attacker to leverage the recvCmd binary to escape from the emulated instance and inject arbitrary commands into the host machine.

  • CVE-2023-1009MedFeb 24, 2023
    risk 0.44cvss 6.5epss 0.16

    ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as critical has been found in DrayTek Vigor 2960 1.5.1.4/1.5.1.5. Affected is the function sub_1DF14 of the file /cgi-bin/mainfunction.cgi of the component Web Management Interface. The manipulation of the argument…

  • CVE-2023-6265MedNov 22, 2023
    risk 0.42cvss 6.5epss 0.02

    ** UNSUPPORTED WHEN ASSIGNED ** Draytek Vigor2960 v1.5.1.4 and v1.5.1.5 are vulnerable to directory traversal via the mainfunction.cgi dumpSyslog 'option' parameter allowing an authenticated attacker with access to the web management interface to delete arbitrary files.…

  • CVE-2023-1163MedMar 3, 2023
    risk 0.42cvss 6.5epss 0.02

    ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability has been found in DrayTek Vigor 2960 1.5.1.4/1.5.1.5 and classified as critical. Affected by this vulnerability is the function getSyslogFile of the file mainfunction.cgi of the component Web Management Interface. The manipulation…

  • CVE-2018-20872MedJul 31, 2019
    risk 0.42cvss 6.5epss 0.01

    DrayTek routers before 2018-05-23 allow CSRF attacks to change DNS or DHCP settings, a related issue to CVE-2017-11649.

  • CVE-2026-71905HigAug 24, 2026
    risk 0.40cvss 7.2epss 0.02

    Multiple DrayTek VigorAP models contain a command injection vulnerability in the ExportSettings function. The vulnerability is caused by insufficient filtering of the backupkey, backuptype, and realtime fields before command execution. A remote attacker can trigger this…

  • CVE-2024-41591MedOct 3, 2024
    risk 0.40cvss 6.1epss 0.00

    DrayTek Vigor3910 devices through 4.3.2.6 allow unauthenticated DOM-based reflected XSS.

  • CVE-2023-23313MedMar 3, 2023
    risk 0.40cvss 6.1epss 0.00

    Certain Draytek products are vulnerable to Cross Site Scripting (XSS) via the wlogin.cgi script and user_login.cgi script of the router's web application management portal. This affects Vigor3910, Vigor1000B, Vigor2962 v4.3.2.1; Vigor2865 and Vigor2866 v4.4.1.0; Vigor2927…

  • CVE-2019-16534MedSep 20, 2019
    risk 0.40cvss 6.1epss 0.01

    On DrayTek Vigor2925 devices with firmware 3.8.4.3, XSS exists via a crafted WAN name on the General Setup screen. NOTE: this is an end-of-life product.

  • CVE-2019-16533MedSep 20, 2019
    risk 0.40cvss 6.1epss 0.01

    On DrayTek Vigor2925 devices with firmware 3.8.4.3, Incorrect Access Control exists in loginset.htm, and can be used to trigger XSS. NOTE: this is an end-of-life product.

  • CVE-2017-11650MedMar 7, 2018
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting (XSS) vulnerability in DrayTek Vigor AP910C devices with firmware 1.2.0_RC3 build r6594 allows remote attackers to inject arbitrary web script or HTML via vectors involving home.asp.

  • CVE-2024-41587MedOct 3, 2024
    risk 0.35cvss 5.4epss 0.00

    Stored XSS, by authenticated users, is caused by poor sanitization of the Login Page Greeting message in DrayTek Vigor310 devices through 4.3.2.6.

  • CVE-2020-28968MedOct 22, 2021
    risk 0.35cvss 5.4epss 0.01

    Draytek VigorAP 1000C contains a stored cross-site scripting (XSS) vulnerability in the RADIUS Setting - RADIUS Server Configuration module. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the username input field.

  • CVE-2021-20128MedOct 13, 2021
    risk 0.35cvss 5.4epss 0.01

    The Profile Name field in the floor plan (Network Menu) page in Draytek VigorConnect 1.6.0-B3 was found to be vulnerable to stored XSS, as user input is not properly sanitized.

  • CVE-2026-71932MedAug 24, 2026
    risk 0.32cvss 4.9epss 0.01

    Multiple DrayTek VigorSwitch models contain a directory traversal vulnerability in the getSyslogFile function. The vulnerability is caused by insufficient validation of the option field. A remote attacker can trigger this vulnerability via crafted input containing path traversal…

  • CVE-2026-71920MedAug 24, 2026
    risk 0.32cvss 4.9epss 0.01

    Multiple DrayTek VigorSwitch models contain a null pointer dereference vulnerability in the formlogout function. The vulnerability is caused by missing checks for an empty or absent Cookie header before string handling. A remote attacker can trigger this vulnerability via a…

  • CVE-2026-3040MedFeb 23, 2026
    risk 0.31cvss 4.7epss 0.07

    A vulnerability was identified in DrayTek Vigor 300B up to 1.5.1.6. This affects the function cgiGetFile of the file /cgi-bin/mainfunction.cgi/uploadlangs of the component Web Management Interface. The manipulation of the argument File leads to os command injection. The attack…

  • CVE-2024-41584MedOct 3, 2024
    risk 0.31cvss 4.7epss 0.00

    DrayTek Vigor3910 devices through 4.3.2.6 are vulnerable to reflected XSS by authenticated users, caused by missing validation of the sFormAuthStr parameter.

  • CVE-2024-41583MedOct 3, 2024
    risk 0.31cvss 4.7epss 0.00

    DrayTek Vigor3910 devices through 4.3.2.6 are vulnerable to stored Cross Site Scripting (XSS) by authenticated users due to poor sanitization of the router name.

  • CVE-2013-5703Oct 22, 2013
    risk 0.00cvss —epss 0.01

    The DrayTek Vigor 2700 router 2.8.3 allows remote attackers to execute arbitrary JavaScript code, and modify settings or the DNS cache, via a crafted SSID value that is not properly handled during insertion into the sWlessSurvey value in variables.js.

Page 4 of 4