Impact
The vulnerability exists in the tr069TestInform function of several DrayTek VigorAP models. Insufficient filtering of special characters in the event_code field allows a crafted input to be concatenated into a system command. This creates a command injection flaw (CWE-78) that can be used by an attacker to run arbitrary commands with root privileges once the exploit is triggered.
Affected Systems
Affected devices are DrayTek VigorAP 1060C, 903, 906, 912C, 918R, and 960C firmware. No specific firmware version range is listed in the CNA data; all releases of these models noted in the advisory are known to be vulnerable.
Risk and Exploitability
The CVSS score of 8.6 classifies this issue as high severity. The EPSS score of 2% and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires valid administrative credentials for the device’s web management interface, implying an authenticated attacker can achieve remote code execution on the device with root access.
OpenCVE Enrichment