Impact
DrayTek VigorSwitch firmware exposes a command injection flaw in the rebDevice function. Insufficient filtering of the username and password parameters allows an attacker to inject shell commands. Successful exploitation grants the attacker full root access to the device, enabling compromise of the switch and potential pivot to the broader network. The weakness is catalogued as CWE‑78, indicating unsanitized input passed to an operating‑system command interpreter.
Affected Systems
The vulnerability affects a range of DrayTek VigorSwitch models, including FX2120, G1280, G1282, G2100, G2121, G2280x, G2282x, G2540x, G2540xs, G2542x, P1280, P1281x, P1282, P2100, P2121, P2280x, P2282x, P2540x, P2540xs, P2542x, P2542xh, PQ2121x, PQ2200xb, PQ2300xb, PX2060, Q2121x, Q2200x, and Q2300x. The affected firmware versions are listed in the vendor’s advisory; any firmware package containing the rebDevice API is vulnerable.
Risk and Exploitability
The CVSS score of 8.6 demonstrates high severity and indicates the risk is significant. The EPSS score indicates a 2% exploitation probability, and the vulnerability is not listed in KEV. The attacker must have valid administrative credentials to the web management interface and can use crafted input to execute arbitrary shell commands. Because the vulnerability requires authentication, it cannot be exploited by unauthenticated users. The potential impact includes full root control over the device, which could be used to disrupt network operations or compromise adjacent systems.
OpenCVE Enrichment