Impact
The vulnerability is a null pointer dereference in the formlogout function caused by missing checks for an empty or absent Cookie header before string handling. This flaw would allow an attacker to crash the web management service, resulting in a denial of service. The impact is that legitimate administrative access would be disrupted until the device is rebooted or the affected firmware is patched.
Affected Systems
Affected devices are DrayTek VigorSwitch models from the VigorSwitch series, including FX2120, G1280, G1282, G2100, G2121, G2280x, G2282x, G2540x, G2540xs, G2542x, P1280, P1281x, P1282, P2100, P2121, P2280x, P2282x, P2540x, P2540xs, P2542x, P2542xh, PQ2121x, PQ2200xb, PQ2300xb, PX2060, Q2121x, Q2200x and Q2300x.
Risk and Exploitability
The CVSS score of 6.9 indicates a medium‑to‑high severity vulnerability. EPSS data is not available, so the exploitation probability is uncertain, but the flaw is not listed in the CISA KEV catalog, suggesting no known active exploitation at the time of analysis. The likely attack vector is a remote, authenticated request to the formlogout endpoint, as the vulnerability requires valid administrative credentials to be exercised. Based on the description, the attack path involves sending a crafted HTTP request with an empty or missing Cookie header to trigger the failure.
OpenCVE Enrichment