Impact
An OS command injection flaw exists in the commandTable function of many DrayTek VigorSwitch router‑switch devices. The vulnerability arises from incomplete sanitization of user‑supplied parameter values, allowing characters such as backticks, newlines, and single quotes to pass through to the underlying shell. A remote attacker who is able to authenticate as an administrator on the device's web management interface can inject and execute arbitrary shell commands with root privileges, potentially compromising the entire switch and the network it serves.
Affected Systems
The affected devices are DrayTek VigorSwitch switches. The flaw is disclosed for a broad set of models, including FX2120, G1280, G1282, G2100, G2121, G2280x, G2282x, G2540x, G2540xs, G2542x, P1280, P1281x, P1282, P2100, P2121, P2280x, P2282x, P2540x, P2540xs, P2542x, P2542xh, PQ2121x, PQ2200xb, PQ2300xb, PX2060, Q2121x, Q2200x, and Q2300x. No specific firmware version range was identified.
Risk and Exploitability
The CVSS base score of 8.6 signals a high‑severity vulnerability, while the EPSS score of 2% indicates a low but non‑negligible likelihood of exploitation. Because the flaw requires only the possession of valid administrative credentials—which is a commonly binded requirement for network device management—the exposure window is significant for organizations that have not hardened web access. The vulnerability is not yet listed in CISA’s KEV catalog, but the combination of remote reach, root‑level impact, and the potential for widespread network compromise warrants immediate attention.
OpenCVE Enrichment