Impact
The flaw is a command injection in the pingtrace feature of DrayTek VigorSwitch devices. Insufficient validation of the host field allows an attacker to craft input that is passed directly to the underlying shell. When triggered, arbitrary commands run with root privileges, enabling full compromise of the device’s operating system. The potential impact includes complete loss of confidentiality, integrity, and availability for the network segment managed by the affected switch. The vulnerability is supported by CWE‑78, indicating the presence of insecure command execution.
Affected Systems
The vulnerability affects a broad range of DrayTek VigorSwitch models, including FX2120, G1280, G1282, G2100, G2121, G2280x, G2282x, G2540x, G2540xs, G2542x, P1280, P1281x, P1282, P2100, P2121, P2280x, P2282x, P2540x, P2540xs, P2542x, P2542xh, PQ2121x, PQ2200xb, PQ2300xb, PX2060, Q2121x, Q2200x, and Q2300x. All firmware versions of these models are unpatched before the advisory date; the affected firmware is identified by the vendor’s citations but no specific version range is provided.
Risk and Exploitability
The CVSS base score of 8.6 classifies the issue as High severity. An EPSS score of 3% indicates a moderate likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires valid administrative credentials to the web management interface, implying that the attacker must either have compromised login credentials or obtained them through other means. Despite this prerequisite, once authenticated, an attacker can execute arbitrary commands with root privileges, making the risk substantial for any exposed or improperly secured management interfaces.
OpenCVE Enrichment