Vigorap 918r Firmware Draytek Vigorap 918r Firmware

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Draytek Vigorap 918r Firmware.

By the Year

In 2026 there have been 11 vulnerabilities in Draytek Vigorap 918r Firmware with an average score of 8.7 out of ten.

Year Vulnerabilities Average Score
2026 11 8.66

It may take a day or so for new Vigorap 918r Firmware vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Draytek Vigorap 918r Firmware Security Vulnerabilities

Command Injection in DrayTek VigorAP upload_settings.cgi
CVE-2026-71913 8.6 - High - August 24, 2026

Multiple DrayTek VigorAP models contain a command injection vulnerability in the upload_settings.cgi interface. The vulnerability is caused by insufficient filtering before the restorekey field is concatenated into a shell command. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administrative credentials for the device's web management interface.

Shell injection

DrayTek VigorAP Command Injection (dray_apm) via UDP START_SPEED_TEST
CVE-2026-71914 9.3 - Critical - August 24, 2026

Multiple DrayTek VigorAP models contain a command injection vulnerability in the dray_apm component. The vulnerability is caused by insufficient validation of UDP message content after START_SPEED_TEST before command execution. A remote attacker can trigger this vulnerability via a crafted message to execute arbitrary commands with root privileges.

Shell injection

DrayTek VigorAP Buffer Overflow in apautotest via CMD6 Field
CVE-2026-71912 8.6 - High - August 24, 2026

Multiple DrayTek VigorAP models contain a buffer overflow vulnerability in the apautotest function. The vulnerability is caused by missing length checks during memory copy operations involving the CMD6 field. A remote attacker can trigger this vulnerability via crafted input, causing a denial of service or potentially executing arbitrary commands. Exploitation requires valid administrative credentials for the device's web management interface.

Classic Buffer Overflow

DrayTek VigorAP cmd injection via web autosteptest (CVE-2026-71910)
CVE-2026-71910 8.6 - High - August 24, 2026

Multiple DrayTek VigorAP models contain a command injection vulnerability in the apautotest function. The vulnerability is caused by insufficient validation of the CMD0, CMD3, and CMD6 fields before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administrative credentials for the device's web management interface.

Shell injection

DrayTek VigorAP setLan Buffer Overflow (CVE-2026-71911)
CVE-2026-71911 8.6 - High - August 24, 2026

Multiple DrayTek VigorAP models contain a buffer overflow vulnerability in the setLan function. The vulnerability is caused by missing length checks during memory copy operations involving the lanVlanId0, lanIp, and lanNetmask fields. A remote attacker can trigger this vulnerability via crafted input, causing a denial of service or potentially executing arbitrary commands. Exploitation requires valid administrative credentials for the device's web management interface.

Classic Buffer Overflow

DrayTek VigorAP cmdinjection via InquireTime time field
CVE-2026-71909 8.6 - High - August 24, 2026

Multiple DrayTek VigorAP models contain a command injection vulnerability in the InquierTime function. The vulnerability is caused by insufficient filtering of the time field before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administrative credentials for the device's web management interface.

Shell injection

Command Injection in DrayTek VigorAP setcamset via SelectSlaves
CVE-2026-71907 8.6 - High - August 24, 2026

Multiple DrayTek VigorAP models contain a command injection vulnerability in the setcamset function. The vulnerability is caused by insufficient filtering of the selectSlaves field before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administrative credentials for the device's web management interface.

Shell injection

Command Injection in DrayTek VigorAP mesh_start_speed_test
CVE-2026-71908 8.6 - High - August 24, 2026

Multiple DrayTek VigorAP models contain a command injection vulnerability in the mesh_start_speed_test function. The vulnerability is caused by insufficient sanitization of the meshdevice_index and meshdevice_ip fields before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administrative credentials for the device's web management interface.

Shell injection

Command Injection in DrayTek VigorAP setLan (CVE-2026-71906)
CVE-2026-71906 8.6 - High - August 24, 2026

Multiple DrayTek VigorAP models contain a command injection vulnerability in the setLan function. The vulnerability is caused by insufficient validation of the lanIp and lanNetmask fields before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administrative credentials for the device's web management interface.

Shell injection

Cmd injection in DrayTek VigorAP tr069TestInform
CVE-2026-71904 8.6 - High - August 24, 2026

Multiple DrayTek VigorAP models contain a command injection vulnerability in the tr069TestInform function. The vulnerability is caused by insufficient filtering of dangerous characters before the event_code field is concatenated into a system command. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administrative credentials for the device's web management interface.

Shell injection

Command Injection in ExportSettings on DrayTek VigorAP (CVE-2026-71905)
CVE-2026-71905 8.6 - High - August 24, 2026

Multiple DrayTek VigorAP models contain a command injection vulnerability in the ExportSettings function. The vulnerability is caused by insufficient filtering of the backupkey, backuptype, and realtime fields before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administrative credentials for the device's web management interface.

Shell injection

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Draytek Vigorap 918r Firmware or by Draytek? Click the Watch button to subscribe.

Draytek
Vendor

subscribe