Vigorswitch Fx2120 Firmware Draytek Vigorswitch Fx2120 Firmware

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Draytek Vigorswitch Fx2120 Firmware.

By the Year

In 2026 there have been 29 vulnerabilities in Draytek Vigorswitch Fx2120 Firmware with an average score of 8.5 out of ten.

Year Vulnerabilities Average Score
2026 29 8.52

It may take a day or so for new Vigorswitch Fx2120 Firmware vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Draytek Vigorswitch Fx2120 Firmware Security Vulnerabilities

Command Injection in DrayTek VigorSwitch setDevNet (root exec)
CVE-2026-71943 8.6 - High - August 24, 2026

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setDevNet function. The vulnerability is caused by insufficient filtering of the username and password fields before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administrative credentials for the device's web management interface.

Shell injection

Buffer Overflow in DrayTek VigorSwitch mail_mailalert Function
CVE-2026-71942 8.6 - High - August 24, 2026

Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the mail_mailalert function. The vulnerability is caused by concatenating multiple smtpReceiver email addresses into a fixed-size buffer without checking the remaining buffer size. A remote attacker can trigger this vulnerability via crafted input, causing a denial of service or potentially executing arbitrary commands. Exploitation requires valid administrative credentials for the device's web management interface.

Classic Buffer Overflow

VigorSwitch diag_logmail buffer overflow via smtpReceiver emails
CVE-2026-71941 8.6 - High - August 24, 2026

Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the diag_logmail function. The vulnerability is caused by concatenating multiple smtpReceiver email addresses into a fixed-size buffer without checking the remaining buffer size. A remote attacker can trigger this vulnerability via crafted input, causing a denial of service or potentially executing arbitrary commands. Exploitation requires valid administrative credentials for the device's web management interface.

Classic Buffer Overflow

DrayTek VigorSwitch acl_general_setup Edit ACE Buffer Overflow (CVE-2026-71940)
CVE-2026-71940 8.6 - High - August 24, 2026

Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the acl_general_setup Edit ACE function. The vulnerability is caused by copying the name field into a fixed-size buffer without length validation. A remote attacker can trigger this vulnerability via crafted input, causing a denial of service or potentially executing arbitrary commands. Exploitation requires valid administrative credentials for the device's web management interface.

Classic Buffer Overflow

DrayTek VigorSwitch ACL buffer overflow via web admin interface
CVE-2026-71939 8.6 - High - August 24, 2026

Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the acl_general_setup Add ACE function. The vulnerability is caused by copying the name field into a fixed-size buffer without length validation. A remote attacker can trigger this vulnerability via crafted input, causing a denial of service or potentially executing arbitrary commands. Exploitation requires valid administrative credentials for the device's web management interface.

Classic Buffer Overflow

DrayTek VigorSwitch buffer overflow in switch_lan_gvrp (CVE-2026-71938)
CVE-2026-71938 8.6 - High - August 24, 2026

Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the switch_lan_gvrp function. The vulnerability is caused by unsafe copying of the portList field into an undersized buffer. A remote attacker can trigger this vulnerability via crafted input, causing a denial of service or potentially executing arbitrary commands. Exploitation requires valid administrative credentials for the device's web management interface.

Classic Buffer Overflow

DrayTek VigorSwitch buffer overflow via poe_schedule_profile
CVE-2026-71937 8.6 - High - August 24, 2026

Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the poe_schedule_profile function. The vulnerability is caused by repeated concatenation of the start_date, start_time, duration_time, how_often, weekdays, monthly_date, and cycle_duration fields into small fixed-size buffers without proper length checks. A remote attacker can trigger this vulnerability via crafted input, causing a denial of service or potentially executing arbitrary commands. Exploitation requires valid administrative credentials for the device's web management interface.

Classic Buffer Overflow

CVE-2026-71936: DrayTek VigorSwitch sysreboot Buffer Overflow
CVE-2026-71936 8.6 - High - August 24, 2026

Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the sysreboot function. The vulnerability is caused by unsafe concatenation of split valueN data into a fixed-size buffer. A remote attacker can trigger this vulnerability via crafted input, causing a denial of service or potentially executing arbitrary commands. Exploitation requires valid administrative credentials for the device's web management interface.

Classic Buffer Overflow

DRYTEK VIGORSWITCH Buffer Overflow in WebBackupAction (remote DoS)
CVE-2026-71935 8.6 - High - August 24, 2026

Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the webBackupAction function. The vulnerability is caused by repeated string concatenation of the pathN, valueN, key, and option fields into fixed-size stack buffers without total length checks. A remote attacker can trigger this vulnerability via crafted input, causing a denial of service or potentially executing arbitrary commands. Exploitation requires valid administrative credentials for the device's web management interface.

Classic Buffer Overflow

DrayTek VigorSwitch Pingtrace Buffer Overflow CVE-2026-71934
CVE-2026-71934 8.6 - High - August 24, 2026

Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the pingtrace function. The vulnerability is caused by missing length checks when the host, count, and interval fields are concatenated into a fixed-size buffer. A remote attacker can trigger this vulnerability via crafted input, causing a denial of service or potentially executing arbitrary commands. Exploitation requires valid administrative credentials for the device's web management interface.

Classic Buffer Overflow

Unauthorized Ops in DrayTek VigorSwitch Syslog
CVE-2026-71933 8.8 - High - August 24, 2026

Multiple DrayTek VigorSwitch models contain unauthorized operation vulnerabilities in multiple syslog functions. The vulnerability is caused by missing authorization checks. A remote attacker can trigger these vulnerabilities via crafted requests to modify configuration, restart services, save startup configuration, or clear logs.

AuthZ

DrayTek VigorSwitch getSyslogFile DIR Traversal
CVE-2026-71932 6.9 - Medium - August 24, 2026

Multiple DrayTek VigorSwitch models contain a directory traversal vulnerability in the getSyslogFile function. The vulnerability is caused by insufficient validation of the option field. A remote attacker can trigger this vulnerability via crafted input containing path traversal sequences to access arbitrary files on the device. Exploitation requires valid administrative credentials for the device's web management interface.

Directory traversal

CmdInjection: DrayTek VigorSwitch tftp_upgrade RCE
CVE-2026-71931 8.6 - High - August 24, 2026

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the tftp_upgrade function. The vulnerability is caused by insufficient filtering before the filename field is concatenated into a command. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administrative credentials for the device's web management interface.

Shell injection

Command Injection in DrayTek VigorSwitch setTime Function
CVE-2026-71930 8.6 - High - August 24, 2026

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setTime function. The vulnerability is caused by insufficient filtering of the username and password fields before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administrative credentials for the device's web management interface.

Shell injection

DrayTek VigorSwitch Command Injection via setDevProto Username/Password Fields
CVE-2026-71929 8.6 - High - August 24, 2026

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setDevProto function. The vulnerability is caused by insufficient filtering of the username and password fields before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administrative credentials for the device's web management interface.

Shell injection

DrayTek VigorSwitch Command Injection via Username/Password in fdftDevice
CVE-2026-71928 8.6 - High - August 24, 2026

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the fdftDevice function. The vulnerability is caused by insufficient filtering of the username and password fields before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administrative credentials for the device's web management interface.

Shell injection

DrayTek VigorSwitch: CmdInjection via rebDevice (CVE202671927)
CVE-2026-71927 8.6 - High - August 24, 2026

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the rebDevice function. The vulnerability is caused by insufficient filtering of the username and password fields before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administrative credentials for the device's web management interface.

Shell injection

Cmd Injection in DrayTek VigorSwitch setDevice (root exec)
CVE-2026-71926 8.6 - High - August 24, 2026

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setDevice function. The vulnerability is caused by insufficient sanitization of the username, password, and location fields before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administrative credentials for the device's web management interface.

Shell injection

Remote Command Injection via getDetail on DrayTek VigorSwitch RCE
CVE-2026-71925 8.6 - High - August 24, 2026

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the getDetail function. The vulnerability is caused by insufficient filtering of the username and password fields before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administrative credentials for the device's web management interface.

Shell injection

Cmd Injection via getVid on DrayTek VigorSwitch
CVE-2026-71924 8.6 - High - August 24, 2026

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the getVid function. The vulnerability is caused by insufficient filtering of the username and password fields before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administrative credentials for the device's web management interface.

Shell injection

Command Injection in DrayTek VigorSwitch Auth_Set via Web UI
CVE-2026-71923 8.6 - High - August 24, 2026

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the auth_set function. The vulnerability is caused by insufficient filtering of the username and password fields before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administrative credentials for the device's web management interface.

Shell injection

DrayTek VigorSwitch NPE in SetGet.cgi Causes DoS
CVE-2026-71922 8.7 - High - August 24, 2026

Multiple DrayTek VigorSwitch models contain a pre-authentication null pointer dereference vulnerability in the setget.cgi interface. The vulnerability is caused by missing validation when the pass field is absent. A remote attacker can trigger this vulnerability via a crafted request to crash the service and cause a denial of service.

NULL Pointer Dereference

Command Injection in DrayTek VigorSwitch setget.cgi (CVE-2026-71921)
CVE-2026-71921 9.3 - Critical - August 24, 2026

Multiple DrayTek VigorSwitch models contain a pre-authentication command injection vulnerability in the setget.cgi interface. The vulnerability is caused by insufficient filtering of the pass field before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges.

Shell injection

VigorSwitch Null Ptr Deref in formLogout Remote DoS
CVE-2026-71920 6.9 - Medium - August 24, 2026

Multiple DrayTek VigorSwitch models contain a null pointer dereference vulnerability in the formlogout function. The vulnerability is caused by missing checks for an empty or absent Cookie header before string handling. A remote attacker can trigger this vulnerability via a crafted request to crash the service and cause a denial of service. Exploitation requires valid administrative credentials for the device's web management interface.

NULL Pointer Dereference

Command Injection in DrayTek VigorSwitch sysreboot
CVE-2026-71919 8.6 - High - August 24, 2026

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the sysreboot function. The vulnerability is caused by insufficient filtering of the config, act, pathN, and valueN fields before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administrative credentials for the device's web management interface.

Shell injection

Command Injection in DrayTek VigorSwitch WebBackupAction (CVE-2026-71918)
CVE-2026-71918 8.6 - High - August 24, 2026

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the webBackupAction function. The vulnerability is caused by insufficient filtering of the option, key, pw_encode, pathN, and valueN fields before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administrative credentials for the device's web management interface.

Shell injection

DrayTek VigorSwitch Cmd Injection via pingtrace (CVE-2026-71917)
CVE-2026-71917 8.6 - High - August 24, 2026

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the pingtrace function. The vulnerability is caused by insufficient validation of the host field before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administrative credentials for the device's web management interface.

Shell injection

Root-Priv Command Injection in DrayTek VigorSwitch commandTable
CVE-2026-71916 8.6 - High - August 24, 2026

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the commandTable function. The vulnerability is caused by incomplete filtering of dangerous characters such as backticks, newline characters, and single quotes in the parameter field. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administrative credentials for the device's web management interface.

Shell injection

DrayTek VigorSwitch cmd injection via jsonstatus (root exec)
CVE-2026-71915 8.6 - High - August 24, 2026

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the jsonstatus function. The vulnerability is caused by insufficient filtering of the usescript, usefile, and option fields before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administrative credentials for the device's web management interface.

Shell injection

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Draytek Vigorswitch Fx2120 Firmware or by Draytek? Click the Watch button to subscribe.

Draytek
Vendor

subscribe