Impact
The vulnerability is a buffer overflow in the setLan function of several DrayTek VigorAP models. The overflow occurs because the firmware does not perform length checks when copying data into the lanVlanId0, lanIp, and lanNetmask fields. A crafted input can overflow the buffer, leading to a denial of service or potentially allowing a remote attacker to execute arbitrary commands, provided the attacker has valid administrative credentials for the device’s web‑management interface.
Affected Systems
Affected devices include DrayTek VigorAP 1060C, 903, 906, 912C, 918R, and 960C. These models run firmware that lacks the necessary bounds checking in the setLan routine. No specific firmware version range is disclosed, so any device running the known vulnerable firmware should be inspected.
Risk and Exploitability
The CVSS base score of 8.6 classifies the flaw as high severity, while the EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires remote access to the web management interface and valid credentials, so the attack vector is remote but credential‑bound. Given the severity and potential for arbitrary code execution, the risk remains significant for exposed or lightly protected devices.
OpenCVE Enrichment