Impact
The vulnerability is a command injection in the sysreboot function of multiple DrayTek VigorSwitch models. Insufficient filtering of the config, act, pathN, and valueN fields allows an attacker to execute arbitrary shell commands with root privileges, which is a classic example of operating system command injection (CWE‑78).
Affected Systems
Affected are DrayTek VigorSwitch FX2120, G1280, G1282, G2100, G2121, G2280x, G2282x, G2540x, G2540xs, G2542x, P1280, P1281x, P1282, P2100, P2121, P2280x, P2282x, P2540x, P2540xs, P2542x, P2542xh, PQ2121x, PQ2200xb, PQ2300xb, PX2060, Q2121x, Q2200x, and Q2300x.
Risk and Exploitability
A CVSS score of 8.6 shows a high severity risk. The Exploit Prediction Scoring System (EPSS) score is 3%, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires a valid administrative login to the device’s web management interface; an attacker with such access can craft malicious input to trigger the sysreboot endpoint and run arbitrary commands with root privileges. The attack vector is therefore remote, mediated through the device’s management network interface.
OpenCVE Enrichment