Impact
This vulnerability arises from inadequate filtering of the username and password fields in the getDetail function of DrayTek VigorSwitch firmware, enabling OS command injection. When triggered, an attacker can run arbitrary commands with root privileges, which can result in full device compromise, persistence, or further network attacks.
Affected Systems
Affected platforms include numerous DrayTek VigorSwitch models: FX2120, G1280, G1282, G2100, G2121, G2280x, G2282x, G2540x, G2540xs, G2542x, P1280, P1281x, P1282, P2100, P2121, P2280x, P2282x, P2540x, P2540xs, P2542x, P2542xh, PQ2121x, PQ2200xb, PQ2300xb, PX2060, Q2121x, Q2200x, Q2300x. No specific firmware version range is listed, so any firmware on these devices may be vulnerable.
Risk and Exploitability
The CVSS score of 8.6 classifies this as high severity, and the EPSS score of 3% indicates a low but non‑zero likelihood of exploitation. Because exploitation requires authenticated access to the web management interface, an attacker must first obtain valid administrative credentials. The vulnerability is not yet listed in CISA KEV, so there is no evidence of widespread exploitation yet. Nonetheless, with valid credentials an attacker can achieve full control over the device.
OpenCVE Enrichment