Description
Multiple DrayTek VigorAP models contain a command injection vulnerability in the dray_apm component. The vulnerability is caused by insufficient validation of UDP message content after START_SPEED_TEST before command execution. A remote attacker can trigger this vulnerability via a crafted message to execute arbitrary commands with root privileges.
Published: 2026-08-24
Score: 9.3 Critical
EPSS: 3.1% Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

A command injection flaw exists in the dray_apm component of several DrayTek VigorAP routers. The flaw stems from inadequate validation of UDP message contents after the START_SPEED_TEST command, allowing a remote attacker to craft a packet that is executed as an operating‑system command. The vulnerability permits execution with root privileges, resulting in full compromise of the affected device and the network to which it is connected.

Affected Systems

The vulnerability affects DrayTek Corporation VigorAP routers: models 1060C, 903, 906, 912C, 918R, and 960C. Firmware details beyond the product names are not supplied in the advisory, so all firmware versions for these models are considered potentially vulnerable until a patch is applied.

Risk and Exploitability

The flaw scores a CVSS of 9.3, indicating a severe threat. EPSS score is 3%, but the vulnerability is pre‑authentication and remote, meaning an attacker can exploit it from outside the local network without needing credentials. The flaw is not yet listed in CISA KEV, suggesting it may not yet have been widely exploited, yet the high score and root-level impact demand urgent attention. The likely attack vector is via UDP traffic to the START_SPEED_TEST port, making network‑driven exploitation straightforward for attackers with remote UDP reach to the device.

Generated by OpenCVE AI on August 25, 2026 at 14:32 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware update from DrayTek that patches the dray_apm command injection flaw.
  • Disable or tightly restrict UDP traffic on the START_SPEED_TEST port to only trusted hosts, or isolate the device on a separate VLAN.
  • Perform network scans to confirm that no untrusted hosts can send START_SPEED_TEST UDP packets to the device, and monitor logs for suspicious command execution attempts.

Generated by OpenCVE AI on August 25, 2026 at 14:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 24 Aug 2026 19:00:00 +0000

Type Values Removed Values Added
First Time appeared Draytek vigorap 1060c
Draytek vigorap 903
Draytek vigorap 906
Draytek vigorap 912c
Draytek vigorap 918r
Draytek vigorap 960c
Vendors & Products Draytek vigorap 1060c
Draytek vigorap 903
Draytek vigorap 906
Draytek vigorap 912c
Draytek vigorap 918r
Draytek vigorap 960c

Mon, 24 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Description Multiple DrayTek VigorAP models contain a command injection vulnerability in the dray_apm component. The vulnerability is caused by insufficient validation of UDP message content after START_SPEED_TEST before command execution. A remote attacker can trigger this vulnerability via a crafted message to execute arbitrary commands with root privileges.
Title DrayTek VigorAP Multiple Models Pre-Authentication OS Command Injection via dray_apm
First Time appeared Draytek
Draytek vigorap 1060c Firmware
Draytek vigorap 903 Firmware
Draytek vigorap 906 Firmware
Draytek vigorap 912c Firmware
Draytek vigorap 918r Firmware
Draytek vigorap 960c Firmware
Weaknesses CWE-78
CPEs cpe:2.3:o:draytek:vigorap_1060c_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:draytek:vigorap_903_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:draytek:vigorap_906_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:draytek:vigorap_912c_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:draytek:vigorap_918r_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:draytek:vigorap_960c_firmware:*:*:*:*:*:*:*:*
Vendors & Products Draytek
Draytek vigorap 1060c Firmware
Draytek vigorap 903 Firmware
Draytek vigorap 906 Firmware
Draytek vigorap 912c Firmware
Draytek vigorap 918r Firmware
Draytek vigorap 960c Firmware
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Draytek Vigorap 1060c Vigorap 1060c Firmware Vigorap 903 Vigorap 903 Firmware Vigorap 906 Vigorap 906 Firmware Vigorap 912c Vigorap 912c Firmware Vigorap 918r Vigorap 918r Firmware Vigorap 960c Vigorap 960c Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-08-24T19:53:39.796Z

Reserved: 2026-08-08T16:37:44.517Z

Link: CVE-2026-71914

cve-icon Vulnrichment

Updated: 2026-08-24T19:53:34.518Z

cve-icon NVD

Status : Deferred

Published: 2026-08-24T18:17:03.497

Modified: 2026-08-26T17:10:09.810

Link: CVE-2026-71914

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T14:45:03Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')