Impact
Multiple DrayTek VigorSwitch models host a pre‑authentication null pointer dereference flaw in the setget.cgi management interface. By omitting the required ‘pass’ field, a bad request can trigger a pointer dereference in the service, leading to an unexpected crash. The flaw falls under CWE‑476 and can be leveraged by a remote attacker to cause a denial of service without authentication.
Affected Systems
Affected systems include a wide array of DrayTek VigorSwitch devices, such as FX2120, G1280, G1282, G2100, G2121, G2280 x, G2282 x, G2540 x, G2540 xs, G2542 x, P1280, P1281 x, P1282, P2100, P2121, P2280 x, P2282 x, P2540 x, P2540 xs, P2542 x, P2542 xh, PQ2121 x, PQ2200 xb, PQ2300 xb, PX2060, Q2121 x, Q2200 x, and Q2300 x. No specific firmware versions are delineated; all listed models are considered vulnerable.
Risk and Exploitability
The CVSS base score of 8.7 classifies this as a high‑severity flaw. EPSS data is missing, so the current exploitation probability is unclear, but the lack of a KEV listing suggests no widespread exploitation yet. The vulnerability is reachable over the network before authentication, implying that an attacker with network access to the management interface can craft a request to crash the service, causing a denial of service for the device and potentially impacting connected clients.
OpenCVE Enrichment