Impact
The vulnerability is an OS command injection in the setLan function of certain DrayTek VigorAP routers. It is caused by the insufficient validation of the lanIp and lanNetmask parameters before they are passed to system commands. A crafted request can therefore cause the device to execute arbitrary operating‑system commands with root privileges, giving the attacker full control over the router and any networks it manages.
Affected Systems
The impacted devices are DrayTek VigorAP 1060C, 903, 906, 912C, 918R, and 960C. All models running the current firmware are compromised.
Risk and Exploitability
The CVSS score of 8.6 classifies the flaw as high severity, and the flaw’s exploitation requires authenticated access to the web management interface but no other prerequisites. The EPSS score is 3%, indicating a modest likelihood of exploitation in real world, but the attack vector remains straightforward for a remote attacker with valid credentials, which increases the practical likelihood of exploitation. The vulnerability is not yet listed in the CISA KEV catalog.
OpenCVE Enrichment