Impact
The vulnerability allows a remote attacker to invoke arbitrary operating‑system commands with root privilege by sending crafted input to the apautotest function. The flaw originates from insufficient validation of the CMD0, CMD3, and CMD6 fields before command execution, which is a classic command injection weakness (CWE‑78).
Affected Systems
Affected devices include the DrayTek VigorAP 1060C, 903, 906, 912C, 918R, and 960C firmware editions. All listed models are susceptible to the command injection in the apautotest endpoint.
Risk and Exploitability
The CVSS score of 8.6 indicates high severity, and the vulnerability requires valid administrative credentials to the web management interface to be exploited. The EPSS score of 3% suggests a low but nonzero probability of exploitation, and the issue is not currently listed in the CISA KEV catalog. The likely attack vector is an authenticated attacker who gains access to the management interface, leveraging the unvalidated parameters to execute arbitrary root‑level commands.
OpenCVE Enrichment