Impact
A stack‑based buffer overflow occurs in the webBackupAction routine of DrayTek VigorSwitch firmware. The implementation concatenates the pathN, valueN, key, and option fields into fixed‑size stack buffers without performing a total length check. An attacker who can authenticate to the device’s web management interface can submit crafted data that overflows the buffer, which may result in a denial of service or the execution of arbitrary commands on the device. The weakness is classified as CWE‑120, indicating an unsafe handling of buffer data.
Affected Systems
The vulnerability affects a wide range of DrayTek VigorSwitch models, including FX2120, G1280, G1282, G2100, G2121, G2280 ×, G2282 ×, G2540 ×, G2540 xs, G2542 ×, P1280, P1281 ×, P1282, P2100, P2121, P2280 ×, P2282 ×, P2540 ×, P2540 xs, P2542 ×, P2542 xh, PQ2121 ×, PQ2200 xb, PQ2300 xb, PX2060, Q2121 ×, Q2200 x, and Q2300 x. The advisory notes that current firmware versions are vulnerable; newer releases fix the flaw.
Risk and Exploitability
The CVSS score of 8.6 indicates a high severity level. While the EPSS score is not available and the vulnerability is not listed in CISA KEV, the requirement for authenticated administrative access reduces the threat to users who can log into the web interface. Based on the description, the attack vector is remote via the web management interface, and exploitation can lead to denial of service or arbitrary code execution, posing a significant impact for any deployed device.
OpenCVE Enrichment