Description
Multiple DrayTek VigorSwitch models contain a directory traversal vulnerability in the getSyslogFile function. The vulnerability is caused by insufficient validation of the option field. A remote attacker can trigger this vulnerability via crafted input containing path traversal sequences to access arbitrary files on the device. Exploitation requires valid administrative credentials for the device's web management interface.
Published: 2026-08-24
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote File Access
Action: Apply Patch
AI Analysis

Impact

A directory traversal flaw in the getSyslogFile function of DrayTek VigorSwitch devices allows a remote attacker who can authenticate to the web management console to request arbitrary files on the device. The vulnerability is caused by insufficient validation of an option field, enabling a crafted request to include traversal sequences such as "../../". Successful exploitation could expose sensitive data, such as configuration files, passwords, or system logs, leading to a confidentiality breach and potentially facilitating further attacks against the network.

Affected Systems

DrayTek Corporation’s VigorSwitch line of switches, including models FX2120, G1280, G1282, G2100, G2121, G2280x, G2282x, G2540x, G2540xs, G2542x, P1280, P1281x, P1282, P2100, P2121, P2280x, P2282x, P2540x, P2540xs, P2542x, P2542xh, PQ2121x, PQ2200xb, PQ2300xb, PX2060, Q2121x, Q2200x, and Q2300x.

Risk and Exploitability

The CVSS score of 6.9 indicates a moderate to high severity that could be leveraged by a malicious actor with administrative access. EPSS data is not available, so the current probability of exploitation is unknown. The vulnerability is not yet listed in the CISA KEV catalogue, but its impact means that any device with a web interface exposed to untrusted networks should be remediated promptly. attackers must have valid administrative credentials; remote exploitation is possible over HTTP/HTTPS to the management interface.

Generated by OpenCVE AI on August 24, 2026 at 18:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the firmware to the latest revision that incorporates the vendor’s fix for the path traversal flaw.
  • If no immediate firmware update is possible, restrict access to the web management interface by IP filtering or disable it entirely from the device configuration.
  • Replace default or weak administrator passwords with strong, unique credentials to reduce the risk of credential compromise.

Generated by OpenCVE AI on August 24, 2026 at 18:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 24 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Description Multiple DrayTek VigorSwitch models contain a directory traversal vulnerability in the getSyslogFile function. The vulnerability is caused by insufficient validation of the option field. A remote attacker can trigger this vulnerability via crafted input containing path traversal sequences to access arbitrary files on the device. Exploitation requires valid administrative credentials for the device's web management interface.
Title DrayTek VigorSwitch Multiple Models Path Traversal via getSyslogFile
First Time appeared Draytek
Draytek vigorswitch Fx2120 Firmware
Draytek vigorswitch G1282 Firmware
Draytek vigorswitch G2100 Firmware
Draytek vigorswitch G2121 Firmware
Draytek vigorswitch G2280x Firmware
Draytek vigorswitch G2540xs Firmware
Draytek vigorswitch P1282 Firmware
Draytek vigorswitch P2100 Firmware
Draytek vigorswitch P2280x Firmware
Draytek vigorswitch P2540xs Firmware
Draytek vigorswitch Pq2121x Firmware
Draytek vigorswitch Pq2200xb Firmware
Draytek vigorswitch Q2121x Firmware
Draytek vigorswitch Q2200x Firmware
Weaknesses CWE-22
CPEs cpe:2.3:o:draytek:vigorswitch_fx2120_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:draytek:vigorswitch_g1282_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:draytek:vigorswitch_g2100_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:draytek:vigorswitch_g2121_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:draytek:vigorswitch_g2280x_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:draytek:vigorswitch_g2540xs_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:draytek:vigorswitch_p1282_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:draytek:vigorswitch_p2100_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:draytek:vigorswitch_p2280x_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:draytek:vigorswitch_p2540xs_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:draytek:vigorswitch_pq2121x_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:draytek:vigorswitch_pq2200xb_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:draytek:vigorswitch_q2121x_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:draytek:vigorswitch_q2200x_firmware:*:*:*:*:*:*:*:*
Vendors & Products Draytek
Draytek vigorswitch Fx2120 Firmware
Draytek vigorswitch G1282 Firmware
Draytek vigorswitch G2100 Firmware
Draytek vigorswitch G2121 Firmware
Draytek vigorswitch G2280x Firmware
Draytek vigorswitch G2540xs Firmware
Draytek vigorswitch P1282 Firmware
Draytek vigorswitch P2100 Firmware
Draytek vigorswitch P2280x Firmware
Draytek vigorswitch P2540xs Firmware
Draytek vigorswitch Pq2121x Firmware
Draytek vigorswitch Pq2200xb Firmware
Draytek vigorswitch Q2121x Firmware
Draytek vigorswitch Q2200x Firmware
References
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Draytek Vigorswitch Fx2120 Firmware Vigorswitch G1282 Firmware Vigorswitch G2100 Firmware Vigorswitch G2121 Firmware Vigorswitch G2280x Firmware Vigorswitch G2540xs Firmware Vigorswitch P1282 Firmware Vigorswitch P2100 Firmware Vigorswitch P2280x Firmware Vigorswitch P2540xs Firmware Vigorswitch Pq2121x Firmware Vigorswitch Pq2200xb Firmware Vigorswitch Q2121x Firmware Vigorswitch Q2200x Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-08-24T18:46:37.804Z

Reserved: 2026-08-08T16:37:44.519Z

Link: CVE-2026-71932

cve-icon Vulnrichment

Updated: 2026-08-24T18:46:28.299Z

cve-icon NVD

Status : Deferred

Published: 2026-08-24T18:17:17.893

Modified: 2026-08-26T17:08:22.300

Link: CVE-2026-71932

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T18:45:05Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')