Impact
A command injection flaw in the jsonstatus function of DrayTek VigorSwitch devices allows a remote, authenticated attacker to supply crafted input that is passed unchecked to the operating system, enabling execution of arbitrary commands with root privileges. The vulnerability arises from insufficient filtering of the usescript, usefile, and option fields and is classified as CWE‑78 (OS Command Injection). Successful exploitation would give an attacker full control over the switch, allowing compromise of the entire network segment to which the device is connected.
Affected Systems
The flaw affects numerous DrayTek VigorSwitch models, including FX2120, G1280, G1282, G2100, G2121, G2280x, G2282x, G2540x, G2540xs, G2542x, P1280, P1281x, P1282, P2100, P2121, P2280x, P2282x, P2540x, P2540xs, P2542x, P2542xh, PQ2121x, PQ2200xb, PQ2300xb, PX2060, Q2121x, Q2200x, and Q2300x—every firmware variant listed in the provided CPE strings is affected.
Risk and Exploitability
The CVSS score of 8.6 indicates high severity, and the vulnerability is not yet listed in the CISA KEV catalog. The EPSS score is 3%, and the requirement for valid administrative credentials for the web‑management interface means that the attack surface is restricted to authenticated users. Once authenticated, an attacker can trigger the vulnerable endpoint and execute commands as root, combining authenticated access with root‑level privilege escalation to deliver a significant security risk for deployments that expose these switches to untrusted networks or the Internet.
OpenCVE Enrichment