Impact
The vulnerability arises from inadequate filtering of the username and password fields before they are used in a system command, allowing a crafted payload to be executed by the device. An attacker can gain complete control of the switch by running arbitrary commands with root privileges, compromising confidentiality, integrity, and availability of the network connected to the switch.
Affected Systems
The flaw affects a broad range of DrayTek VigorSwitch models, including FX2120, G1280, G1282, G2100, G2121, G2280x, G2282x, G2540x, G2540xs, G2542x, P1280, P1281x, P2540x, P2540xs, P2542x, P2542xh, PQ2121x, PQ2200xb, Q2121x, Q2200x and Q2300x, as identified by the CNA in the advisory.
Risk and Exploitability
The CVSS score of 8.6 indicates high severity, and the willingness of an attacker is heightened by the high impact and root privileges obtained. The EPSS score is 3%, indicating a low but non-zero exploitation probability and implying a small chance the vulnerability might be exploited in the wild. The vulnerability is not listed in CISA KEV, meaning no confirmed exploits are publicly known. The likely attack vector is the device’s web management interface, which requires valid administrative credentials; once authenticated, an attacker can send malicious input to the setDevProto API and trigger shell execution.
OpenCVE Enrichment