Impact
The vulnerability is an operating system command injection flaw in the fdftDevice function due to insufficient filtering of the username and password fields before command execution. A remote attacker, possessing valid administrative credentials for the device’s web management interface, can craft input that causes the system to run arbitrary commands with root privileges. The result is a complete compromise of the affected Switch allowing the attacker to alter configuration, exfiltrate data, or pivot to other network assets.
Affected Systems
DrayTek VigorSwitch models including FX2120, G1280, G1282, G2100, G2121, G2280x, G2282x, G2540x, G2540xs, G2542x, P1280, P1281x, P1282, P2100, P2121, P2280x, P2282x, P2540x, P2540xs, P2542x, P2542xh, PQ2121x, PQ2200xb, PQ2300xb, PX2060, Q2121x, Q2200x, and Q2300x.
Risk and Exploitability
The CVSS score of 8.6 classifies this fault as high severity, and the EPSS score of 0.01666% indicates a very low probability that this vulnerability will be exploited in the near term. The potential for arbitrary root‑level command execution makes exploitation highly impactful. The vulnerability is exploitable from anywhere that can reach the web interface; it requires prior authentication but does not demand privileges beyond administrative credentials. Since the vulnerability is not listed in CISA KEV and no public exploit is cited, the likelihood of active exploitation remains uncertain, but the exposed web interface makes it a significant threat if the device is reachable over the network.
OpenCVE Enrichment