Impact
This vulnerability arises from insufficient filtering of the username and password parameters in the getVid function of DrayTek VigorSwitch devices. By submitting specially crafted input while logged into the web‑management interface, an attacker can inject arbitrary operating‑system commands that execute as root. The result is full control over the device, allowing the attacker to tamper with configuration, redirect traffic, or use the switch as a pivot within the network.
Affected Systems
The flaw affects a wide range of DrayTek VigorSwitch models, including the FX2120, G1280 series, G2100 series, G2280x, G2540x series, P1280 series, Q2121x and Q2200x models, among others. Firmware versions supplied to these devices prior to the advisory contain the vulnerable getVid implementation; no specific firmware revision numbers are yet listed to be safe.
Risk and Exploitability
The CVSS score of 8.6 indicates a high severity vulnerability. The EPSS score of 3% reflects a moderate probability of exploitation, and the lack of listing in the CISA KEV catalog suggests no documented active exploit as of the advisory date. Exploitation requires valid administrative credentials to the web interface, so an attacker would first need to gain or guess these credentials or target a device whose management interface is exposed to the internet or an untrusted internal segment. Once compromised, the attacker could execute arbitrary commands with system-level privileges, posing a substantial threat to the device and potentially the broader network.
OpenCVE Enrichment