Impact
An insufficiently filtered username and password in the auth_set function allows a remote attacker to inject arbitrary commands into the router’s operating system. When successful, the attacker can execute shell commands with root privileges via the web management interface, potentially compromising the entire device and any connected network. The flaw is a classic OS command injection and is listed as CWE‑78.
Affected Systems
DrayTek’s VigorSwitch series is affected, including FX2120, G1280, G1282, G2100, G2121, G2280x, G2282x, G2540x, G2540xs, G2542x, P1280, P1281x, P1282, P2100, P2121, P2280x, P2282x, P2540x, P2540xs, P2542x, P2542xh, Q2121x, Q2200x, Q2300x and PQ2121x models. The listed firmware versions in the CPE data cover the broad product line but do not specify exact vulnerable build dates. Heads‑up for admins of any model powered by the affected firmware.
Risk and Exploitability
The CVSS score of 8.6 indicates high severity, and the EPSS score of 2% shows a low but non‑zero likelihood of exploitation. The lack of a KEV listing does not diminish the risk. Attackers must first obtain valid administrative credentials for the web interface, after which the crafted username or password input can be used to run arbitrary root commands. The exploit would be conducted via the web interface, so it requires network connectivity to the device’s management port and possession of a legitimate admin account.
OpenCVE Enrichment