Impact
The affected firmware contains a command injection flaw in the upload_settings.cgi handler. An attacker who can submit a crafted restorekey value will cause that value to be concatenated into a shell command without proper sanitization. The flaw is a CWE‑78 vulnerability that permits an exploiter with administrative web‑interface credentials to run arbitrary commands as the root user, effectively giving complete control over the network device.
Affected Systems
The issue affects DrayTek VigorAP routers of the 1060C, 903, 906, 912C, 918R, and 960C models. No specific firmware build numbers are disclosed, so all firmware versions that include the upload_settings.cgi script are potentially vulnerable until a patch is released.
Risk and Exploitability
The CVSS score of 8.6 indicates high impact. The EPSS score is 2%, but the vulnerability is already documented as exploitable and not listed in the CISA KEV list. Attack requires remote access to the web portal with valid administrative credentials; the exploit is carried out by sending a specially crafted HTTP request that injects shell commands. As a result, an attacker gains root-level access to the router, jeopardizing confidentiality, integrity, and availability of the network equipment.
OpenCVE Enrichment