Impact
Multiple DrayTek VigorSwitch models are affected by a command injection flaw in the setDevice function. The vulnerability stems from inadequate sanitization of the username, password, and location fields before they are passed to the operating system. Because the injected payload is executed with root privileges, an attacker can run any command with full system control. Exploitation requires that the attacker supplies valid administrative credentials to the web management interface, after which the attacker can create, modify, or delete configuration data or take complete control of the device.
Affected Systems
DrayTek VigorSwitch devices, including FX2120, G1280, G1282, G2100, G2121, G2280x, G2282x, G2540x, G2540xs, G2542x, P1280, P1281x, P2540x, P2540xs, P2542x, P2542xh, PQ2121x, PQ2200xb, PQ2300xb, PX2060, Q2121x, Q2200x, Q2300x, are impacted.
Risk and Exploitability
The CVSS score of 8.6 indicates a high severity impact, while the EPSS score is 2%, indicating a low but non-zero exploitation probability. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is via the web management interface: an attacker must authenticate with valid administrative credentials and then submit crafted input to the setDevice API. The flaw allows remote execution of arbitrary commands with root privileges, presenting a significant risk to confidentiality, integrity, and availability of the device and any network it serves.
OpenCVE Enrichment