Impact
The vulnerability is a buffer overflow in the pingtrace function of DrayTek VigorSwitch firmware. Missing length checks when the host, count, and interval fields are concatenated into a fixed‑size buffer allow a crafted input to overflow the buffer. An attacker with valid administrative credentials can trigger the overflow via the web management interface, leading to a denial of service or potentially executing arbitrary commands on the device.
Affected Systems
Affected devices include a range of DrayTek VigorSwitch models such as FX2120, G1280, G1282, G2100, G2121, G2280x, G2282x, G2540x, G2540xs, G2542x, P1280, P1281x, P1282, P2100, P2121, P2280x, P2282x, P2540x, P2540xs, P2542x, P2542xh, PQ2121x, PQ2200xb, PQ2300xb, PX2060, Q2121x, Q2200x, Q2300x, as well as the firmware variations noted in the vendor’s advisory.
Risk and Exploitability
The CVSS base score of 8.6 categorizes this flaw as high severity, while the EPSS score is not available, indicating uncertainty about exploitation frequency. Because the attack requires authenticated administrative access to the web interface, it is not exploitable from an unauthenticated network. The vulnerability is not yet listed in the CISA KEV catalog, but the high score and the ability to achieve remote code execution make it a priority for immediate remediation.
OpenCVE Enrichment