Description
Multiple DrayTek VigorAP models contain a command injection vulnerability in the tr069TestInform function. The vulnerability is caused by insufficient filtering of dangerous characters before the event_code field is concatenated into a system command. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administrative credentials for the device's web management interface.
Published: 2026-08-24
Score: 8.6 High
EPSS: 2.4% Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability exists in the tr069TestInform function of several DrayTek VigorAP models. Insufficient filtering of special characters in the event_code field allows a crafted input to be concatenated into a system command. This creates a command injection flaw (CWE-78) that can be used by an attacker to run arbitrary commands with root privileges once the exploit is triggered.

Affected Systems

Affected devices are DrayTek VigorAP 1060C, 903, 906, 912C, 918R, and 960C firmware. No specific firmware version range is listed in the CNA data; all releases of these models noted in the advisory are known to be vulnerable.

Risk and Exploitability

The CVSS score of 8.6 classifies this issue as high severity. The EPSS score of 2% and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires valid administrative credentials for the device’s web management interface, implying an authenticated attacker can achieve remote code execution on the device with root access.

Generated by OpenCVE AI on August 25, 2026 at 14:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update all affected VigorAP devices to the latest firmware version recommended by DrayTek in the security advisory.
  • Restrict access to the web management interface by limiting connections to trusted IP ranges or placing the device behind a firewall that requires VPN authentication.
  • Enforce strong, unique administrative passwords and enable two‑factor authentication if the device supports it to reduce the risk of credential compromise.

Generated by OpenCVE AI on August 25, 2026 at 14:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 24 Aug 2026 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Draytek vigorap 1060c
Draytek vigorap 903
Draytek vigorap 906
Draytek vigorap 912c
Draytek vigorap 918r
Draytek vigorap 960c
Vendors & Products Draytek vigorap 1060c
Draytek vigorap 903
Draytek vigorap 906
Draytek vigorap 912c
Draytek vigorap 918r
Draytek vigorap 960c

Mon, 24 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Description Multiple DrayTek VigorAP models contain a command injection vulnerability in the tr069TestInform function. The vulnerability is caused by insufficient filtering of dangerous characters before the event_code field is concatenated into a system command. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administrative credentials for the device's web management interface.
Title DrayTek VigorAP Multiple Models OS Command Injection via tr069TestInform
First Time appeared Draytek
Draytek vigorap 1060c Firmware
Draytek vigorap 903 Firmware
Draytek vigorap 906 Firmware
Draytek vigorap 912c Firmware
Draytek vigorap 918r Firmware
Draytek vigorap 960c Firmware
Weaknesses CWE-78
CPEs cpe:2.3:o:draytek:vigorap_1060c_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:draytek:vigorap_903_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:draytek:vigorap_906_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:draytek:vigorap_912c_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:draytek:vigorap_918r_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:draytek:vigorap_960c_firmware:*:*:*:*:*:*:*:*
Vendors & Products Draytek
Draytek vigorap 1060c Firmware
Draytek vigorap 903 Firmware
Draytek vigorap 906 Firmware
Draytek vigorap 912c Firmware
Draytek vigorap 918r Firmware
Draytek vigorap 960c Firmware
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Draytek Vigorap 1060c Vigorap 1060c Firmware Vigorap 903 Vigorap 903 Firmware Vigorap 906 Vigorap 906 Firmware Vigorap 912c Vigorap 912c Firmware Vigorap 918r Vigorap 918r Firmware Vigorap 960c Vigorap 960c Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-08-24T19:52:30.570Z

Reserved: 2026-08-08T16:37:44.517Z

Link: CVE-2026-71904

cve-icon Vulnrichment

Updated: 2026-08-24T19:52:26.863Z

cve-icon NVD

Status : Deferred

Published: 2026-08-24T18:17:01.700

Modified: 2026-08-26T17:10:09.810

Link: CVE-2026-71904

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T14:45:03Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')