Impact
The flaw is an OS command injection in the setTime function of a wide range of DrayTek VigorSwitch devices. Due to insufficient filtering of username and password fields before execution, a remote attacker can embed malicious commands that are run as root. This vulnerability is classified as CWE‑78, indicating an improper constraint on OS command execution. The result is complete system compromise, allowing the attacker to compromise confidentiality, integrity, and availability of the network device and any connected infrastructure.
Affected Systems
Affected are numerous DrayTek VigorSwitch models including FX2120, G1280, G1282, G2100, G2121, G2280x, G2282x, G2540x, G2540xs, G2542x, P1280, P1281x, P1282, P2100, P2121, P2280x, P2282x, P2540x, P2540xs, P2542x, P2542xh, PQ2121x, PQ2200xb, PQ2300xb, PX2060, Q2121x, Q2200x, and Q2300x. All listed models are running firmware containing the vulnerable setTime implementation.
Risk and Exploitability
The CVSS score of 8.6 categorizes the issue as high severity. The EPSS score of 3% indicates a moderately low probability of exploitation, but the vulnerability is present on all devices with web management enabled. The attack vector is remote via the web interface; however, valid administrative credentials are mandatory to exploit the flaw. The vulnerability is not presently listed in the CISA KEV catalog, but the inherent severity and the need for credential compromise still pose a significant risk to organizations relying on these switches.
OpenCVE Enrichment