Impact
This flaw is an OS command injection (CWE-78) in the mesh_start_speed_test routine of several DrayTek VigorAP firmware releases. The lack of validation on the meshdevice_index and meshdevice_ip parameters lets a crafted web request be passed straight to the underlying shell, allowing an attacker who has logged into the web management interface with administrative privileges to run arbitrary commands as root. The ability to execute system commands with elevated rights turns the device into a fully compromised endpoint, exposing all configuration, network traffic, and potentially any user data passing through the access point.
Affected Systems
The vulnerability affects DrayTek VigorAP 1060C, VigorAP 903, VigorAP 906, VigorAP 912C, VigorAP 918R, and VigorAP 960C models. All firmware versions shipped before DrayTek’s official patch are vulnerable; administrators should confirm the device model and firmware revision before applying any remediation.
Risk and Exploitability
The CVSS score of 8.6 signals high severity, while the EPSS score is 3%, indicating a moderate exploitation probability. The flaw requires valid administrative credentials to the web interface, so the attack surface is restricted to individuals who can access that interface, either locally or remotely. Because the vulnerability is not listed in CISA’s KEV catalog, there is no evidence yet of large‑scale exploitation. Nevertheless, the potential for full root‑level takeover warrants immediate attention.
OpenCVE Enrichment