Description
Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the tftp_upgrade function. The vulnerability is caused by insufficient filtering before the filename field is concatenated into a command. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administrative credentials for the device's web management interface.
Published: 2026-08-24
Score: 8.6 High
EPSS: 2.4% Low
KEV: No
Impact: Remote Command Execution
Action: Immediate Patch
AI Analysis

Impact

This vulnerability arises in the tftp_upgrade function of DrayTek VigorSwitch firmware. The software fails to sanitize the filename parameter before appending it to a system command, allowing a remote attacker who can authenticate to the device's web management interface to inject and execute arbitrary root‑privileged commands. The impact is loss of confidentiality, integrity, and availability of the device and the associated network.

Affected Systems

The flaw affects a wide range of DrayTek VigorSwitch units, including the FX2120, G1280, G1282, G2100, G2121, G2280x, G2282x, G2540x, G2540xs, G2542x, P1280, P1281x, P1282, P2100, P2121, P2280x, P2282x, P2540x, P2540xs, P2542x, P2542xh, PQ2121x, PQ2200xb, PQ2300xb, PX2060, Q2121x, Q2200x, and Q2300x. All firmware versions of these models are potentially vulnerable; no specific firmware versions are listed.

Risk and Exploitability

The CVSS score of 8.6 indicates a high severity flaw. Because the attack requires valid administrator credentials to the web interface, the EPSS score is 2%, and the vulnerability is not presently listed in the CISA KEV catalog, the likelihood of widespread exploitation remains uncertain but the low EPSS suggests a relatively low exploitation probability. However, once authenticated, the attacker can run arbitrary commands with system‑level privileges and potentially cause a full device compromise. The likely attack vector is the web management interface accessed over the LAN or the Internet.

Generated by OpenCVE AI on August 25, 2026 at 14:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Deploy the vendor‑issued firmware update that patches the tftp_upgrade command‑injection flaw on all affected VigorSwitch models.
  • Restrict administrative access to the web interface by applying firewall rules, VPN‑only access, or isolating the device from untrusted networks.
  • Disable the tftp_upgrade feature if it is not required for your environment, or ensure it uses a secure, authenticated channel to prevent unauthorized use.
  • Enforce strong, unique administrative passwords and enable multi‑factor authentication if supported by the device.

Generated by OpenCVE AI on August 25, 2026 at 14:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 24 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Description Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the tftp_upgrade function. The vulnerability is caused by insufficient filtering before the filename field is concatenated into a command. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administrative credentials for the device's web management interface.
Title DrayTek VigorSwitch Multiple Models OS Command Injection via tftp_upgrade
First Time appeared Draytek
Draytek vigorswitch Fx2120 Firmware
Draytek vigorswitch G1282 Firmware
Draytek vigorswitch G2100 Firmware
Draytek vigorswitch G2121 Firmware
Draytek vigorswitch G2280x Firmware
Draytek vigorswitch G2540xs Firmware
Draytek vigorswitch P1282 Firmware
Draytek vigorswitch P2100 Firmware
Draytek vigorswitch P2280x Firmware
Draytek vigorswitch P2540xs Firmware
Draytek vigorswitch Pq2121x Firmware
Draytek vigorswitch Pq2200xb Firmware
Draytek vigorswitch Q2121x Firmware
Draytek vigorswitch Q2200x Firmware
Weaknesses CWE-78
CPEs cpe:2.3:o:draytek:vigorswitch_fx2120_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:draytek:vigorswitch_g1282_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:draytek:vigorswitch_g2100_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:draytek:vigorswitch_g2121_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:draytek:vigorswitch_g2280x_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:draytek:vigorswitch_g2540xs_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:draytek:vigorswitch_p1282_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:draytek:vigorswitch_p2100_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:draytek:vigorswitch_p2280x_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:draytek:vigorswitch_p2540xs_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:draytek:vigorswitch_pq2121x_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:draytek:vigorswitch_pq2200xb_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:draytek:vigorswitch_q2121x_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:draytek:vigorswitch_q2200x_firmware:*:*:*:*:*:*:*:*
Vendors & Products Draytek
Draytek vigorswitch Fx2120 Firmware
Draytek vigorswitch G1282 Firmware
Draytek vigorswitch G2100 Firmware
Draytek vigorswitch G2121 Firmware
Draytek vigorswitch G2280x Firmware
Draytek vigorswitch G2540xs Firmware
Draytek vigorswitch P1282 Firmware
Draytek vigorswitch P2100 Firmware
Draytek vigorswitch P2280x Firmware
Draytek vigorswitch P2540xs Firmware
Draytek vigorswitch Pq2121x Firmware
Draytek vigorswitch Pq2200xb Firmware
Draytek vigorswitch Q2121x Firmware
Draytek vigorswitch Q2200x Firmware
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Draytek Vigorswitch Fx2120 Firmware Vigorswitch G1282 Firmware Vigorswitch G2100 Firmware Vigorswitch G2121 Firmware Vigorswitch G2280x Firmware Vigorswitch G2540xs Firmware Vigorswitch P1282 Firmware Vigorswitch P2100 Firmware Vigorswitch P2280x Firmware Vigorswitch P2540xs Firmware Vigorswitch Pq2121x Firmware Vigorswitch Pq2200xb Firmware Vigorswitch Q2121x Firmware Vigorswitch Q2200x Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-08-27T13:51:25.835Z

Reserved: 2026-08-08T16:37:44.518Z

Link: CVE-2026-71931

cve-icon Vulnrichment

Updated: 2026-08-27T13:51:20.661Z

cve-icon NVD

Status : Deferred

Published: 2026-08-24T18:17:17.697

Modified: 2026-08-27T17:19:48.677

Link: CVE-2026-71931

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T15:00:13Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')