Impact
The vulnerability is an OS command injection that can be triggered before any authentication is required. An attacker can send specially crafted input to the setget.cgi interface, causing the device to execute arbitrary commands with root privileges. This allows full compromise of the device, including data exfiltration, denial of service, or use as a pivot to other systems on the network. The weakness is a classic command injection scenario reflected in CWE-78.
Affected Systems
The flaw affects a broad range of DrayTek VigorSwitch network switches, including models FX2120, G1280, G1282, G2100, G2121, G2280x, G2282x, G2540x, G2540xs, G2542x, P1280, P1281x, P1282, P2100, P2121, P2280x, P2282x, P2540x, P2540xs, P2542x, P2542xh, PQ2121x, PQ2200xb, PQ2300xb, PX2060, Q2121x, Q2200x, and Q2300x. Firmware versions where the setget.cgi handler lacks proper input filtering are not provided in the advisory; users should confirm the vulnerability on their devices by reviewing the vendor’s release notes for the affected firmware.
Risk and Exploitability
With a CVSS score of 9.3, the vulnerability is deemed critical. The EPSS score of 3% indicates a low but non‑zero exploitation probability, but the high severity combined with the pre‑authentication nature suggests that exploitation is possible from any network that can reach the web interface. The device is not listed in CISA’s KEV catalog, yet the attack surface remains significant for organizations deploying these switches.
OpenCVE Enrichment