Impact
The vulnerability is an OS command injection in the webBackupAction handler of DrayTek VigorSwitch firmware. Insufficient filtering of the option, key, pw_encode, pathN, and valueN fields allows a remote user who has authenticated to the web management interface to inject arbitrary shell commands that are executed with root privileges. This flaw grants full control over the device, enabling the attacker to tamper with configurations, exfiltrate data, or pivot to other network assets. Based on the description, it is inferred that the command injection occurs within the webBackupAction request handling process.
Affected Systems
The flaw affects a broad range of DrayTek VigorSwitch models, including FX2120, G1280, G1282, G2100, G2121, G2280x, G2282x, G2540x, G2540xs, G2542x, P1280, P1281x, P2540x, P2540xs, PQ2121x, PQ2200xb, Q2121x, Q2200x, and Q2300x devices running the affected firmware.
Risk and Exploitability
The CVSS v3 score of 8.6 reflects high severity combined with the requirement for authenticated access. The EPSS score of 3% indicates a moderate potential for exploitation, and the vulnerability is not listed in the CISA KEV catalog. The potential for root‑level execution means that once an attacker gains interface credentials—whether through credential theft, default passwords, or other means—the risk escalates dramatically. The likely attack path is through the authenticated web management interface; an attacker with credentials can issue crafted webBackupAction requests from within the same network or if the interface is exposed externally, thereby bypassing external network defenses.
OpenCVE Enrichment