Description
Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setDevice function. The vulnerability is caused by insufficient sanitization of the username, password, and location fields before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administrative credentials for the device's web management interface.
Published: 2026-08-24
Score: 8.6 High
EPSS: 1.7% Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

Multiple DrayTek VigorSwitch models are affected by a command injection flaw in the setDevice function. The vulnerability stems from inadequate sanitization of the username, password, and location fields before they are passed to the operating system. Because the injected payload is executed with root privileges, an attacker can run any command with full system control. Exploitation requires that the attacker supplies valid administrative credentials to the web management interface, after which the attacker can create, modify, or delete configuration data or take complete control of the device.

Affected Systems

DrayTek VigorSwitch devices, including FX2120, G1280, G1282, G2100, G2121, G2280x, G2282x, G2540x, G2540xs, G2542x, P1280, P1281x, P2540x, P2540xs, P2542x, P2542xh, PQ2121x, PQ2200xb, PQ2300xb, PX2060, Q2121x, Q2200x, Q2300x, are impacted.

Risk and Exploitability

The CVSS score of 8.6 indicates a high severity impact, while the EPSS score is 2%, indicating a low but non-zero exploitation probability. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is via the web management interface: an attacker must authenticate with valid administrative credentials and then submit crafted input to the setDevice API. The flaw allows remote execution of arbitrary commands with root privileges, presenting a significant risk to confidentiality, integrity, and availability of the device and any network it serves.

Generated by OpenCVE AI on August 25, 2026 at 14:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware update for the affected VigorSwitch models as announced by DrayTek.
  • Limit access to the device’s web management interface to trusted hosts or a VPN tunnel only.
  • Change default or weak administrator passwords and disable any unused accounts.

Generated by OpenCVE AI on August 25, 2026 at 14:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 27 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 24 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Description Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setDevice function. The vulnerability is caused by insufficient sanitization of the username, password, and location fields before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administrative credentials for the device's web management interface.
Title DrayTek VigorSwitch Multiple Models OS Command Injection via setDevice
First Time appeared Draytek
Draytek vigorswitch Fx2120 Firmware
Draytek vigorswitch G1282 Firmware
Draytek vigorswitch G2100 Firmware
Draytek vigorswitch G2121 Firmware
Draytek vigorswitch G2280x Firmware
Draytek vigorswitch G2540xs Firmware
Draytek vigorswitch P1282 Firmware
Draytek vigorswitch P2100 Firmware
Draytek vigorswitch P2280x Firmware
Draytek vigorswitch P2540xs Firmware
Draytek vigorswitch Pq2121x Firmware
Draytek vigorswitch Pq2200xb Firmware
Draytek vigorswitch Q2121x Firmware
Draytek vigorswitch Q2200x Firmware
Weaknesses CWE-78
CPEs cpe:2.3:o:draytek:vigorswitch_fx2120_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:draytek:vigorswitch_g1282_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:draytek:vigorswitch_g2100_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:draytek:vigorswitch_g2121_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:draytek:vigorswitch_g2280x_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:draytek:vigorswitch_g2540xs_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:draytek:vigorswitch_p1282_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:draytek:vigorswitch_p2100_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:draytek:vigorswitch_p2280x_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:draytek:vigorswitch_p2540xs_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:draytek:vigorswitch_pq2121x_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:draytek:vigorswitch_pq2200xb_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:draytek:vigorswitch_q2121x_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:draytek:vigorswitch_q2200x_firmware:*:*:*:*:*:*:*:*
Vendors & Products Draytek
Draytek vigorswitch Fx2120 Firmware
Draytek vigorswitch G1282 Firmware
Draytek vigorswitch G2100 Firmware
Draytek vigorswitch G2121 Firmware
Draytek vigorswitch G2280x Firmware
Draytek vigorswitch G2540xs Firmware
Draytek vigorswitch P1282 Firmware
Draytek vigorswitch P2100 Firmware
Draytek vigorswitch P2280x Firmware
Draytek vigorswitch P2540xs Firmware
Draytek vigorswitch Pq2121x Firmware
Draytek vigorswitch Pq2200xb Firmware
Draytek vigorswitch Q2121x Firmware
Draytek vigorswitch Q2200x Firmware
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Draytek Vigorswitch Fx2120 Firmware Vigorswitch G1282 Firmware Vigorswitch G2100 Firmware Vigorswitch G2121 Firmware Vigorswitch G2280x Firmware Vigorswitch G2540xs Firmware Vigorswitch P1282 Firmware Vigorswitch P2100 Firmware Vigorswitch P2280x Firmware Vigorswitch P2540xs Firmware Vigorswitch Pq2121x Firmware Vigorswitch Pq2200xb Firmware Vigorswitch Q2121x Firmware Vigorswitch Q2200x Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-08-27T13:50:32.141Z

Reserved: 2026-08-08T16:37:44.518Z

Link: CVE-2026-71926

cve-icon Vulnrichment

Updated: 2026-08-27T13:50:26.660Z

cve-icon NVD

Status : Deferred

Published: 2026-08-24T18:17:07.977

Modified: 2026-08-27T17:19:48.190

Link: CVE-2026-71926

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T15:00:13Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')