Impact
This vulnerability arises in the tftp_upgrade function of DrayTek VigorSwitch firmware. The software fails to sanitize the filename parameter before appending it to a system command, allowing a remote attacker who can authenticate to the device's web management interface to inject and execute arbitrary root‑privileged commands. The impact is loss of confidentiality, integrity, and availability of the device and the associated network.
Affected Systems
The flaw affects a wide range of DrayTek VigorSwitch units, including the FX2120, G1280, G1282, G2100, G2121, G2280x, G2282x, G2540x, G2540xs, G2542x, P1280, P1281x, P1282, P2100, P2121, P2280x, P2282x, P2540x, P2540xs, P2542x, P2542xh, PQ2121x, PQ2200xb, PQ2300xb, PX2060, Q2121x, Q2200x, and Q2300x. All firmware versions of these models are potentially vulnerable; no specific firmware versions are listed.
Risk and Exploitability
The CVSS score of 8.6 indicates a high severity flaw. Because the attack requires valid administrator credentials to the web interface, the EPSS score is 2%, and the vulnerability is not presently listed in the CISA KEV catalog, the likelihood of widespread exploitation remains uncertain but the low EPSS suggests a relatively low exploitation probability. However, once authenticated, the attacker can run arbitrary commands with system‑level privileges and potentially cause a full device compromise. The likely attack vector is the web management interface accessed over the LAN or the Internet.
OpenCVE Enrichment