Draytek Vigorap 903 Firmware
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Draytek Vigorap 903 Firmware.
By the Year
In 2026 there have been 11 vulnerabilities in Draytek Vigorap 903 Firmware with an average score of 8.7 out of ten.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 11 | 8.66 |
It may take a day or so for new Vigorap 903 Firmware vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Draytek Vigorap 903 Firmware Security Vulnerabilities
Command Injection in DrayTek VigorAP upload_settings.cgi
CVE-2026-71913
8.6 - High
- August 24, 2026
Multiple DrayTek VigorAP models contain a command injection vulnerability in the upload_settings.cgi interface. The vulnerability is caused by insufficient filtering before the restorekey field is concatenated into a shell command. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administrative credentials for the device's web management interface.
Shell injection
DrayTek VigorAP Command Injection (dray_apm) via UDP START_SPEED_TEST
CVE-2026-71914
9.3 - Critical
- August 24, 2026
Multiple DrayTek VigorAP models contain a command injection vulnerability in the dray_apm component. The vulnerability is caused by insufficient validation of UDP message content after START_SPEED_TEST before command execution. A remote attacker can trigger this vulnerability via a crafted message to execute arbitrary commands with root privileges.
Shell injection
DrayTek VigorAP Buffer Overflow in apautotest via CMD6 Field
CVE-2026-71912
8.6 - High
- August 24, 2026
Multiple DrayTek VigorAP models contain a buffer overflow vulnerability in the apautotest function. The vulnerability is caused by missing length checks during memory copy operations involving the CMD6 field. A remote attacker can trigger this vulnerability via crafted input, causing a denial of service or potentially executing arbitrary commands. Exploitation requires valid administrative credentials for the device's web management interface.
Classic Buffer Overflow
DrayTek VigorAP cmd injection via web autosteptest (CVE-2026-71910)
CVE-2026-71910
8.6 - High
- August 24, 2026
Multiple DrayTek VigorAP models contain a command injection vulnerability in the apautotest function. The vulnerability is caused by insufficient validation of the CMD0, CMD3, and CMD6 fields before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administrative credentials for the device's web management interface.
Shell injection
DrayTek VigorAP setLan Buffer Overflow (CVE-2026-71911)
CVE-2026-71911
8.6 - High
- August 24, 2026
Multiple DrayTek VigorAP models contain a buffer overflow vulnerability in the setLan function. The vulnerability is caused by missing length checks during memory copy operations involving the lanVlanId0, lanIp, and lanNetmask fields. A remote attacker can trigger this vulnerability via crafted input, causing a denial of service or potentially executing arbitrary commands. Exploitation requires valid administrative credentials for the device's web management interface.
Classic Buffer Overflow
DrayTek VigorAP cmdinjection via InquireTime time field
CVE-2026-71909
8.6 - High
- August 24, 2026
Multiple DrayTek VigorAP models contain a command injection vulnerability in the InquierTime function. The vulnerability is caused by insufficient filtering of the time field before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administrative credentials for the device's web management interface.
Shell injection
Command Injection in DrayTek VigorAP setcamset via SelectSlaves
CVE-2026-71907
8.6 - High
- August 24, 2026
Multiple DrayTek VigorAP models contain a command injection vulnerability in the setcamset function. The vulnerability is caused by insufficient filtering of the selectSlaves field before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administrative credentials for the device's web management interface.
Shell injection
Command Injection in DrayTek VigorAP mesh_start_speed_test
CVE-2026-71908
8.6 - High
- August 24, 2026
Multiple DrayTek VigorAP models contain a command injection vulnerability in the mesh_start_speed_test function. The vulnerability is caused by insufficient sanitization of the meshdevice_index and meshdevice_ip fields before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administrative credentials for the device's web management interface.
Shell injection
Command Injection in DrayTek VigorAP setLan (CVE-2026-71906)
CVE-2026-71906
8.6 - High
- August 24, 2026
Multiple DrayTek VigorAP models contain a command injection vulnerability in the setLan function. The vulnerability is caused by insufficient validation of the lanIp and lanNetmask fields before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administrative credentials for the device's web management interface.
Shell injection
Cmd injection in DrayTek VigorAP tr069TestInform
CVE-2026-71904
8.6 - High
- August 24, 2026
Multiple DrayTek VigorAP models contain a command injection vulnerability in the tr069TestInform function. The vulnerability is caused by insufficient filtering of dangerous characters before the event_code field is concatenated into a system command. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administrative credentials for the device's web management interface.
Shell injection
Command Injection in ExportSettings on DrayTek VigorAP (CVE-2026-71905)
CVE-2026-71905
8.6 - High
- August 24, 2026
Multiple DrayTek VigorAP models contain a command injection vulnerability in the ExportSettings function. The vulnerability is caused by insufficient filtering of the backupkey, backuptype, and realtime fields before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administrative credentials for the device's web management interface.
Shell injection
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Draytek Vigorap 903 Firmware or by Draytek? Click the Watch button to subscribe.