Impact
A command injection flaw exists in the dray_apm component of several DrayTek VigorAP routers. The flaw stems from inadequate validation of UDP message contents after the START_SPEED_TEST command, allowing a remote attacker to craft a packet that is executed as an operating‑system command. The vulnerability permits execution with root privileges, resulting in full compromise of the affected device and the network to which it is connected.
Affected Systems
The vulnerability affects DrayTek Corporation VigorAP routers: models 1060C, 903, 906, 912C, 918R, and 960C. Firmware details beyond the product names are not supplied in the advisory, so all firmware versions for these models are considered potentially vulnerable until a patch is applied.
Risk and Exploitability
The flaw scores a CVSS of 9.3, indicating a severe threat. EPSS score is 3%, but the vulnerability is pre‑authentication and remote, meaning an attacker can exploit it from outside the local network without needing credentials. The flaw is not yet listed in CISA KEV, suggesting it may not yet have been widely exploited, yet the high score and root-level impact demand urgent attention. The likely attack vector is via UDP traffic to the START_SPEED_TEST port, making network‑driven exploitation straightforward for attackers with remote UDP reach to the device.
OpenCVE Enrichment