Impact
Multiple DrayTek VigorAP models contain a command injection vulnerability in the ExportSettings function. The vulnerability is caused by insufficient filtering of the backupkey, backuptype, and realtime fields before command execution. A remote attacker can craft malicious input to these fields, causing the device to execute arbitrary operating system commands with root privileges. This flaw is a classic command injection (CWE-78) that, if exploited, allows an attacker to gain full control of the affected router, potentially compromising confidentiality, integrity, and availability of the network and any systems behind the router.
Affected Systems
Affected devices are DrayTek VigorAP routers, specifically models 1060C, 903, 906, 912C, 918R, and 960C. The vulnerability is present in the firmware that includes the ExportSettings function; no specific firmware version pinning is provided, so all current firmware for these models is assumed affected until a patch is applied.
Risk and Exploitability
The CVSS score of 8.6 indicates a high severity RCE vulnerability. The EPSS score of 3% shows a moderate likelihood of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires valid administrative credentials to the device's web management interface, after which the attacker can execute arbitrary commands remotely. The potential impact is complete control of the device and any resources it is connected to.
OpenCVE Enrichment