Draytek Draytek

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in any Draytek product.

RSS Feeds for Draytek security vulnerabilities

Create a CVE RSS feed including security vulnerabilities found in Draytek products with stack.watch. Just hit watch, then grab your custom RSS feed url.

Products by Draytek Sorted by Most Security Vulnerabilities since 2018

Draytek Vigor3910 Firmware45 vulnerabilities

Draytek Vigor3900 Firmware35 vulnerabilities

Draytek Vigorap 960c Firmware11 vulnerabilities

Draytek Vigorap 918r Firmware11 vulnerabilities

Draytek Vigorap 912c Firmware11 vulnerabilities

Draytek Vigorap 906 Firmware11 vulnerabilities

Draytek Vigorap 903 Firmware11 vulnerabilities

Draytek Vigorap 1060c Firmware11 vulnerabilities

Draytek Vigor2960 Firmware5 vulnerabilities

Draytek Vigor 2960 Firmware2 vulnerabilities

Draytek Vigor 29601 vulnerability

Known Exploited Draytek Vulnerabilities

The following Draytek vulnerabilities have been marked by CISA as Known to be Exploited by threat actors.

Title Description Added
DrayTek Vigor Routers OS Command Injection Vulnerability DrayTek Vigor2960, Vigor300B, and Vigor3900 routers contain an OS command injection vulnerability due to an unknown function of the file /cgi-bin/mainfunction.cgi/apmcfgupload of the component web management interface.
CVE-2024-12987 Exploit Probability: 98.1%
May 15, 2025
DrayTek Multiple Vigor Routers OS Command Injection Vulnerability DrayTek Vigor3900, Vigor2960, and Vigor300B devices contain an OS command injection vulnerability in cgi-bin/mainfunction.cgi/cvmcfgupload that allows for remote code execution via shell metacharacters in a filename when the text/x-python-script content type is used.
CVE-2020-15415 Exploit Probability: 84.5%
September 30, 2024
Draytek VigorConnect Path Traversal Vulnerability Draytek VigorConnect contains a path traversal vulnerability in the file download functionality of the WebServlet endpoint. An unauthenticated attacker could leverage this vulnerability to download arbitrary files from the underlying operating system with root privileges.
CVE-2021-20124 Exploit Probability: 96.3%
September 3, 2024
Draytek VigorConnect Path Traversal Vulnerability Draytek VigorConnect contains a path traversal vulnerability in the DownloadFileServlet endpoint. An unauthenticated attacker could leverage this vulnerability to download arbitrary files from the underlying operating system with root privileges.
CVE-2021-20123 Exploit Probability: 90.2%
September 3, 2024
DrayTek Vigor Router Vulnerability DrayTek Vigor2960 1.3.1_Beta, Vigor3900 1.4.4_Beta, and Vigor300B 1.3.3_Beta, 1.4.2.1_Beta, and 1.4.4_Beta devices allow remote code execution as root (without authentication) via shell metacharacters to the cgi-bin/mainfunction.cgi URI.
CVE-2020-8515 Exploit Probability: 100.0%
November 3, 2021

Of the known exploited vulnerabilities above, 5 are in the top 1%, or the 99th percentile of the EPSS exploit probability rankings.

By the Year

In 2026 there have been 42 vulnerabilities in Draytek with an average score of 8.5 out of ten. Draytek did not have any published security vulnerabilities last year. That is, 42 more vulnerabilities have already been reported in 2026 as compared to last year.




Year Vulnerabilities Average Score
2026 42 8.45
2025 0 0.00
2024 81 7.67
2023 6 7.75
2022 0 0.00
2021 7 7.50
2020 1 9.80

It may take a day or so for new Draytek vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Draytek Security Vulnerabilities

CVE Date Vulnerability Products
CVE-2026-71943 Aug 24, 2026
Command Injection in DrayTek VigorSwitch setDevNet (root exec) Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setDevNet function. The vulnerability is caused by insufficient filtering of the username and password fields before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administrative credentials for the device's web management interface.
Vigorswitch G2540xs Firmware
Vigorswitch P2540xs Firmware
Vigorswitch Fx2120 Firmware
And others...
CVE-2026-71942 Aug 24, 2026
Buffer Overflow in DrayTek VigorSwitch mail_mailalert Function Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the mail_mailalert function. The vulnerability is caused by concatenating multiple smtpReceiver email addresses into a fixed-size buffer without checking the remaining buffer size. A remote attacker can trigger this vulnerability via crafted input, causing a denial of service or potentially executing arbitrary commands. Exploitation requires valid administrative credentials for the device's web management interface.
Vigorswitch G2540xs Firmware
Vigorswitch P2540xs Firmware
Vigorswitch Fx2120 Firmware
And others...
CVE-2026-71941 Aug 24, 2026
VigorSwitch diag_logmail buffer overflow via smtpReceiver emails Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the diag_logmail function. The vulnerability is caused by concatenating multiple smtpReceiver email addresses into a fixed-size buffer without checking the remaining buffer size. A remote attacker can trigger this vulnerability via crafted input, causing a denial of service or potentially executing arbitrary commands. Exploitation requires valid administrative credentials for the device's web management interface.
Vigorswitch G2540xs Firmware
Vigorswitch P2540xs Firmware
Vigorswitch Fx2120 Firmware
And others...
CVE-2026-71940 Aug 24, 2026
DrayTek VigorSwitch acl_general_setup Edit ACE Buffer Overflow (CVE-2026-71940) Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the acl_general_setup Edit ACE function. The vulnerability is caused by copying the name field into a fixed-size buffer without length validation. A remote attacker can trigger this vulnerability via crafted input, causing a denial of service or potentially executing arbitrary commands. Exploitation requires valid administrative credentials for the device's web management interface.
Vigorswitch G2540xs Firmware
Vigorswitch P2540xs Firmware
Vigorswitch Fx2120 Firmware
And others...
CVE-2026-71939 Aug 24, 2026
DrayTek VigorSwitch ACL buffer overflow via web admin interface Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the acl_general_setup Add ACE function. The vulnerability is caused by copying the name field into a fixed-size buffer without length validation. A remote attacker can trigger this vulnerability via crafted input, causing a denial of service or potentially executing arbitrary commands. Exploitation requires valid administrative credentials for the device's web management interface.
Vigorswitch G2540xs Firmware
Vigorswitch P2540xs Firmware
Vigorswitch Fx2120 Firmware
And others...
CVE-2026-71938 Aug 24, 2026
DrayTek VigorSwitch buffer overflow in switch_lan_gvrp (CVE-2026-71938) Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the switch_lan_gvrp function. The vulnerability is caused by unsafe copying of the portList field into an undersized buffer. A remote attacker can trigger this vulnerability via crafted input, causing a denial of service or potentially executing arbitrary commands. Exploitation requires valid administrative credentials for the device's web management interface.
Vigorswitch G2540xs Firmware
Vigorswitch P2540xs Firmware
Vigorswitch Fx2120 Firmware
And others...
CVE-2026-71937 Aug 24, 2026
DrayTek VigorSwitch buffer overflow via poe_schedule_profile Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the poe_schedule_profile function. The vulnerability is caused by repeated concatenation of the start_date, start_time, duration_time, how_often, weekdays, monthly_date, and cycle_duration fields into small fixed-size buffers without proper length checks. A remote attacker can trigger this vulnerability via crafted input, causing a denial of service or potentially executing arbitrary commands. Exploitation requires valid administrative credentials for the device's web management interface.
Vigorswitch G2540xs Firmware
Vigorswitch P2540xs Firmware
Vigorswitch Fx2120 Firmware
And others...
CVE-2026-71936 Aug 24, 2026
CVE-2026-71936: DrayTek VigorSwitch sysreboot Buffer Overflow Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the sysreboot function. The vulnerability is caused by unsafe concatenation of split valueN data into a fixed-size buffer. A remote attacker can trigger this vulnerability via crafted input, causing a denial of service or potentially executing arbitrary commands. Exploitation requires valid administrative credentials for the device's web management interface.
Vigorswitch G2540xs Firmware
Vigorswitch P2540xs Firmware
Vigorswitch Fx2120 Firmware
And others...
CVE-2026-71935 Aug 24, 2026
DRYTEK VIGORSWITCH Buffer Overflow in WebBackupAction (remote DoS) Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the webBackupAction function. The vulnerability is caused by repeated string concatenation of the pathN, valueN, key, and option fields into fixed-size stack buffers without total length checks. A remote attacker can trigger this vulnerability via crafted input, causing a denial of service or potentially executing arbitrary commands. Exploitation requires valid administrative credentials for the device's web management interface.
Vigorswitch G2540xs Firmware
Vigorswitch P2540xs Firmware
Vigorswitch Fx2120 Firmware
And others...
CVE-2026-71934 Aug 24, 2026
DrayTek VigorSwitch Pingtrace Buffer Overflow CVE-2026-71934 Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the pingtrace function. The vulnerability is caused by missing length checks when the host, count, and interval fields are concatenated into a fixed-size buffer. A remote attacker can trigger this vulnerability via crafted input, causing a denial of service or potentially executing arbitrary commands. Exploitation requires valid administrative credentials for the device's web management interface.
Vigorswitch G2540xs Firmware
Vigorswitch P2540xs Firmware
Vigorswitch Fx2120 Firmware
And others...
CVE-2026-71933 Aug 24, 2026
Unauthorized Ops in DrayTek VigorSwitch Syslog Multiple DrayTek VigorSwitch models contain unauthorized operation vulnerabilities in multiple syslog functions. The vulnerability is caused by missing authorization checks. A remote attacker can trigger these vulnerabilities via crafted requests to modify configuration, restart services, save startup configuration, or clear logs.
Vigorswitch G2540xs Firmware
Vigorswitch P2540xs Firmware
Vigorswitch Fx2120 Firmware
And others...
CVE-2026-71932 Aug 24, 2026
DrayTek VigorSwitch getSyslogFile DIR Traversal Multiple DrayTek VigorSwitch models contain a directory traversal vulnerability in the getSyslogFile function. The vulnerability is caused by insufficient validation of the option field. A remote attacker can trigger this vulnerability via crafted input containing path traversal sequences to access arbitrary files on the device. Exploitation requires valid administrative credentials for the device's web management interface.
Vigorswitch G2540xs Firmware
Vigorswitch P2540xs Firmware
Vigorswitch Fx2120 Firmware
And others...
CVE-2026-71931 Aug 24, 2026
CmdInjection: DrayTek VigorSwitch tftp_upgrade RCE Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the tftp_upgrade function. The vulnerability is caused by insufficient filtering before the filename field is concatenated into a command. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administrative credentials for the device's web management interface.
Vigorswitch G2540xs Firmware
Vigorswitch P2540xs Firmware
Vigorswitch Fx2120 Firmware
And others...
CVE-2026-71930 Aug 24, 2026
Command Injection in DrayTek VigorSwitch setTime Function Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setTime function. The vulnerability is caused by insufficient filtering of the username and password fields before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administrative credentials for the device's web management interface.
Vigorswitch G2540xs Firmware
Vigorswitch P2540xs Firmware
Vigorswitch Fx2120 Firmware
And others...
CVE-2026-71929 Aug 24, 2026
DrayTek VigorSwitch Command Injection via setDevProto Username/Password Fields Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setDevProto function. The vulnerability is caused by insufficient filtering of the username and password fields before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administrative credentials for the device's web management interface.
Vigorswitch G2540xs Firmware
Vigorswitch P2540xs Firmware
Vigorswitch Fx2120 Firmware
And others...
CVE-2026-71928 Aug 24, 2026
DrayTek VigorSwitch Command Injection via Username/Password in fdftDevice Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the fdftDevice function. The vulnerability is caused by insufficient filtering of the username and password fields before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administrative credentials for the device's web management interface.
Vigorswitch G2540xs Firmware
Vigorswitch P2540xs Firmware
Vigorswitch Fx2120 Firmware
And others...
CVE-2026-71927 Aug 24, 2026
DrayTek VigorSwitch: CmdInjection via rebDevice (CVE202671927) Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the rebDevice function. The vulnerability is caused by insufficient filtering of the username and password fields before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administrative credentials for the device's web management interface.
Vigorswitch G2540xs Firmware
Vigorswitch P2540xs Firmware
Vigorswitch Fx2120 Firmware
And others...
CVE-2026-71926 Aug 24, 2026
Cmd Injection in DrayTek VigorSwitch setDevice (root exec) Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setDevice function. The vulnerability is caused by insufficient sanitization of the username, password, and location fields before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administrative credentials for the device's web management interface.
Vigorswitch G2540xs Firmware
Vigorswitch P2540xs Firmware
Vigorswitch Fx2120 Firmware
And others...
CVE-2026-71925 Aug 24, 2026
Remote Command Injection via getDetail on DrayTek VigorSwitch RCE Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the getDetail function. The vulnerability is caused by insufficient filtering of the username and password fields before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administrative credentials for the device's web management interface.
Vigorswitch G2540xs Firmware
Vigorswitch P2540xs Firmware
Vigorswitch Fx2120 Firmware
And others...
CVE-2026-71924 Aug 24, 2026
Cmd Injection via getVid on DrayTek VigorSwitch Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the getVid function. The vulnerability is caused by insufficient filtering of the username and password fields before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administrative credentials for the device's web management interface.
Vigorswitch G2540xs Firmware
Vigorswitch P2540xs Firmware
Vigorswitch Fx2120 Firmware
And others...
CVE-2026-71923 Aug 24, 2026
Command Injection in DrayTek VigorSwitch Auth_Set via Web UI Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the auth_set function. The vulnerability is caused by insufficient filtering of the username and password fields before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administrative credentials for the device's web management interface.
Vigorswitch G2540xs Firmware
Vigorswitch P2540xs Firmware
Vigorswitch Fx2120 Firmware
And others...
CVE-2026-71922 Aug 24, 2026
DrayTek VigorSwitch NPE in SetGet.cgi Causes DoS Multiple DrayTek VigorSwitch models contain a pre-authentication null pointer dereference vulnerability in the setget.cgi interface. The vulnerability is caused by missing validation when the pass field is absent. A remote attacker can trigger this vulnerability via a crafted request to crash the service and cause a denial of service.
Vigorswitch G2540xs Firmware
Vigorswitch P2540xs Firmware
Vigorswitch Fx2120 Firmware
And others...
CVE-2026-71921 Aug 24, 2026
Command Injection in DrayTek VigorSwitch setget.cgi (CVE-2026-71921) Multiple DrayTek VigorSwitch models contain a pre-authentication command injection vulnerability in the setget.cgi interface. The vulnerability is caused by insufficient filtering of the pass field before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges.
Vigorswitch G2540xs Firmware
Vigorswitch P2540xs Firmware
Vigorswitch Fx2120 Firmware
And others...
CVE-2026-71920 Aug 24, 2026
VigorSwitch Null Ptr Deref in formLogout Remote DoS Multiple DrayTek VigorSwitch models contain a null pointer dereference vulnerability in the formlogout function. The vulnerability is caused by missing checks for an empty or absent Cookie header before string handling. A remote attacker can trigger this vulnerability via a crafted request to crash the service and cause a denial of service. Exploitation requires valid administrative credentials for the device's web management interface.
Vigorswitch G2540xs Firmware
Vigorswitch P2540xs Firmware
Vigorswitch Fx2120 Firmware
And others...
CVE-2026-71919 Aug 24, 2026
Command Injection in DrayTek VigorSwitch sysreboot Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the sysreboot function. The vulnerability is caused by insufficient filtering of the config, act, pathN, and valueN fields before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administrative credentials for the device's web management interface.
Vigorswitch G2540xs Firmware
Vigorswitch P2540xs Firmware
Vigorswitch Fx2120 Firmware
And others...
CVE-2026-71918 Aug 24, 2026
Command Injection in DrayTek VigorSwitch WebBackupAction (CVE-2026-71918) Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the webBackupAction function. The vulnerability is caused by insufficient filtering of the option, key, pw_encode, pathN, and valueN fields before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administrative credentials for the device's web management interface.
Vigorswitch G2540xs Firmware
Vigorswitch P2540xs Firmware
Vigorswitch Fx2120 Firmware
And others...
CVE-2026-71917 Aug 24, 2026
DrayTek VigorSwitch Cmd Injection via pingtrace (CVE-2026-71917) Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the pingtrace function. The vulnerability is caused by insufficient validation of the host field before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administrative credentials for the device's web management interface.
Vigorswitch G2540xs Firmware
Vigorswitch P2540xs Firmware
Vigorswitch Fx2120 Firmware
And others...
CVE-2026-71916 Aug 24, 2026
Root-Priv Command Injection in DrayTek VigorSwitch commandTable Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the commandTable function. The vulnerability is caused by incomplete filtering of dangerous characters such as backticks, newline characters, and single quotes in the parameter field. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administrative credentials for the device's web management interface.
Vigorswitch G2540xs Firmware
Vigorswitch P2540xs Firmware
Vigorswitch Fx2120 Firmware
And others...
CVE-2026-71915 Aug 24, 2026
DrayTek VigorSwitch cmd injection via jsonstatus (root exec) Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the jsonstatus function. The vulnerability is caused by insufficient filtering of the usescript, usefile, and option fields before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administrative credentials for the device's web management interface.
Vigorswitch G2540xs Firmware
Vigorswitch P2540xs Firmware
Vigorswitch Fx2120 Firmware
And others...
CVE-2026-71913 Aug 24, 2026
Command Injection in DrayTek VigorAP upload_settings.cgi Multiple DrayTek VigorAP models contain a command injection vulnerability in the upload_settings.cgi interface. The vulnerability is caused by insufficient filtering before the restorekey field is concatenated into a shell command. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administrative credentials for the device's web management interface.
Vigorap 918r Firmware
Vigorap 960c Firmware
Vigorap 1060c Firmware
And others...
CVE-2026-71914 Aug 24, 2026
DrayTek VigorAP Command Injection (dray_apm) via UDP START_SPEED_TEST Multiple DrayTek VigorAP models contain a command injection vulnerability in the dray_apm component. The vulnerability is caused by insufficient validation of UDP message content after START_SPEED_TEST before command execution. A remote attacker can trigger this vulnerability via a crafted message to execute arbitrary commands with root privileges.
Vigorap 918r Firmware
Vigorap 960c Firmware
Vigorap 1060c Firmware
And others...
CVE-2026-71912 Aug 24, 2026
DrayTek VigorAP Buffer Overflow in apautotest via CMD6 Field Multiple DrayTek VigorAP models contain a buffer overflow vulnerability in the apautotest function. The vulnerability is caused by missing length checks during memory copy operations involving the CMD6 field. A remote attacker can trigger this vulnerability via crafted input, causing a denial of service or potentially executing arbitrary commands. Exploitation requires valid administrative credentials for the device's web management interface.
Vigorap 918r Firmware
Vigorap 960c Firmware
Vigorap 1060c Firmware
And others...
CVE-2026-71911 Aug 24, 2026
DrayTek VigorAP setLan Buffer Overflow (CVE-2026-71911) Multiple DrayTek VigorAP models contain a buffer overflow vulnerability in the setLan function. The vulnerability is caused by missing length checks during memory copy operations involving the lanVlanId0, lanIp, and lanNetmask fields. A remote attacker can trigger this vulnerability via crafted input, causing a denial of service or potentially executing arbitrary commands. Exploitation requires valid administrative credentials for the device's web management interface.
Vigorap 918r Firmware
Vigorap 960c Firmware
Vigorap 1060c Firmware
And others...
CVE-2026-71910 Aug 24, 2026
DrayTek VigorAP cmd injection via web autosteptest (CVE-2026-71910) Multiple DrayTek VigorAP models contain a command injection vulnerability in the apautotest function. The vulnerability is caused by insufficient validation of the CMD0, CMD3, and CMD6 fields before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administrative credentials for the device's web management interface.
Vigorap 918r Firmware
Vigorap 960c Firmware
Vigorap 1060c Firmware
And others...
CVE-2026-71909 Aug 24, 2026
DrayTek VigorAP cmdinjection via InquireTime time field Multiple DrayTek VigorAP models contain a command injection vulnerability in the InquierTime function. The vulnerability is caused by insufficient filtering of the time field before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administrative credentials for the device's web management interface.
Vigorap 918r Firmware
Vigorap 960c Firmware
Vigorap 1060c Firmware
And others...
CVE-2026-71908 Aug 24, 2026
Command Injection in DrayTek VigorAP mesh_start_speed_test Multiple DrayTek VigorAP models contain a command injection vulnerability in the mesh_start_speed_test function. The vulnerability is caused by insufficient sanitization of the meshdevice_index and meshdevice_ip fields before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administrative credentials for the device's web management interface.
Vigorap 918r Firmware
Vigorap 960c Firmware
Vigorap 1060c Firmware
And others...
CVE-2026-71907 Aug 24, 2026
Command Injection in DrayTek VigorAP setcamset via SelectSlaves Multiple DrayTek VigorAP models contain a command injection vulnerability in the setcamset function. The vulnerability is caused by insufficient filtering of the selectSlaves field before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administrative credentials for the device's web management interface.
Vigorap 918r Firmware
Vigorap 960c Firmware
Vigorap 1060c Firmware
And others...
CVE-2026-71906 Aug 24, 2026
Command Injection in DrayTek VigorAP setLan (CVE-2026-71906) Multiple DrayTek VigorAP models contain a command injection vulnerability in the setLan function. The vulnerability is caused by insufficient validation of the lanIp and lanNetmask fields before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administrative credentials for the device's web management interface.
Vigorap 918r Firmware
Vigorap 960c Firmware
Vigorap 1060c Firmware
And others...
CVE-2026-71905 Aug 24, 2026
Command Injection in ExportSettings on DrayTek VigorAP (CVE-2026-71905) Multiple DrayTek VigorAP models contain a command injection vulnerability in the ExportSettings function. The vulnerability is caused by insufficient filtering of the backupkey, backuptype, and realtime fields before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administrative credentials for the device's web management interface.
Vigorap 918r Firmware
Vigorap 960c Firmware
Vigorap 1060c Firmware
And others...
CVE-2026-71904 Aug 24, 2026
Cmd injection in DrayTek VigorAP tr069TestInform Multiple DrayTek VigorAP models contain a command injection vulnerability in the tr069TestInform function. The vulnerability is caused by insufficient filtering of dangerous characters before the event_code field is concatenated into a system command. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administrative credentials for the device's web management interface.
Vigorap 918r Firmware
Vigorap 960c Firmware
Vigorap 1060c Firmware
And others...
CVE-2022-50994 May 08, 2026
DrayTek Vigor 2960 OS Cmd Injection via formpassword (pre1.5.1.4) DrayTek Vigor 2960 firmware versions prior to 1.5.1.4 contain an OS command injection vulnerability in the CGI login handler that allows unauthenticated remote attackers to execute arbitrary commands by injecting shell metacharacters into the formpassword parameter. Attackers can exploit unsanitized input passed to the otp_check.sh script to achieve remote code execution with web server privileges. Exploitation requires knowledge of a valid username and that the target account has MOTP authentication enabled.
Vigor 2960
CVE-2026-3040 Feb 23, 2026
DrayTek Vigor 300B 1.5.1.6 Web Mgmt: CGI os cmd injection via File A vulnerability was identified in DrayTek Vigor 300B up to 1.5.1.6. This affects the function cgiGetFile of the file /cgi-bin/mainfunction.cgi/uploadlangs of the component Web Management Interface. The manipulation of the argument File leads to os command injection. The attack may be initiated remotely. The exploit is publicly available and might be used. The vendor confirms that "300B is EoL, and this is an authenticated vulnerability. We don't plan to fix it." This vulnerability only affects products that are no longer supported by the maintainer.
CVE-2024-12987 Dec 27, 2024
DrayTek Vigor2960 and Vigor300B Web Management Interface OS Command Injection Vulnerability A vulnerability, which was classified as critical, was found in DrayTek Vigor2960 and Vigor300B 1.5.1.4. Affected is an unknown function of the file /cgi-bin/mainfunction.cgi/apmcfgupload of the component Web Management Interface. The manipulation of the argument session leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.5.1.5 is able to address this issue. It is recommended to upgrade the affected component.
CVE-2024-45884 Nov 04, 2024
DrayTek Vigor3900 1.5.1.3 CGI Command Injection DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `setSWMGroup.`
Vigor3900 Firmware
CVE-2024-45888 Nov 04, 2024
DrayTek Vigor3900 CGI Command Injection DrayTek Vigor3900 1.5.1.3 contains a command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `set_ap_map_config.'
Vigor3900 Firmware
CVE-2024-45885 Nov 04, 2024
DrayTek Vigor3900 1.5.1.3 CGI Command Injection DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `autodiscovery_clear.`
Vigor3900 Firmware
CVE-2024-45893 Nov 04, 2024
DrayTek Vigor3900 1.5.1.3 CGI Command Injection DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `setSWMOption.`
Vigor3900 Firmware
CVE-2024-45891 Nov 04, 2024
DrayTek Vigor3900 1.5.1.3 CGI Command Injection DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `delete_wlan_profile.`
Vigor3900 Firmware
CVE-2024-45890 Nov 04, 2024
DrayTek Vigor3900 1.5.1.3 CGI Command Injection DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `download_ovpn.`
Vigor3900 Firmware
CVE-2024-45889 Nov 04, 2024
DrayTek Vigor3900 1.5.1.3 CGI Command Injection DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `commandTable.`
Vigor3900 Firmware
Built by Foundeo Inc., with data from the National Vulnerability Database (NVD). Privacy Policy. Use of this site is governed by the Legal Terms
Disclaimer
CONTENT ON THIS WEBSITE IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. Always check with your vendor for the most up to date, and accurate information.