Description
Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the webBackupAction function. The vulnerability is caused by repeated string concatenation of the pathN, valueN, key, and option fields into fixed-size stack buffers without total length checks. A remote attacker can trigger this vulnerability via crafted input, causing a denial of service or potentially executing arbitrary commands. Exploitation requires valid administrative credentials for the device's web management interface.
Published: 2026-08-24
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

A stack‑based buffer overflow occurs in the webBackupAction routine of DrayTek VigorSwitch firmware. The implementation concatenates the pathN, valueN, key, and option fields into fixed‑size stack buffers without performing a total length check. An attacker who can authenticate to the device’s web management interface can submit crafted data that overflows the buffer, which may result in a denial of service or the execution of arbitrary commands on the device. The weakness is classified as CWE‑120, indicating an unsafe handling of buffer data.

Affected Systems

The vulnerability affects a wide range of DrayTek VigorSwitch models, including FX2120, G1280, G1282, G2100, G2121, G2280 ×, G2282 ×, G2540 ×, G2540 xs, G2542 ×, P1280, P1281 ×, P1282, P2100, P2121, P2280 ×, P2282 ×, P2540 ×, P2540 xs, P2542 ×, P2542 xh, PQ2121 ×, PQ2200 xb, PQ2300 xb, PX2060, Q2121 ×, Q2200 x, and Q2300 x. The advisory notes that current firmware versions are vulnerable; newer releases fix the flaw.

Risk and Exploitability

The CVSS score of 8.6 indicates a high severity level. While the EPSS score is not available and the vulnerability is not listed in CISA KEV, the requirement for authenticated administrative access reduces the threat to users who can log into the web interface. Based on the description, the attack vector is remote via the web management interface, and exploitation can lead to denial of service or arbitrary code execution, posing a significant impact for any deployed device.

Generated by OpenCVE AI on August 24, 2026 at 19:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware update from DrayTek that addresses the webBackupAction buffer overflow.
  • If a patch is not yet available, disable the web management interface or restrict access to trusted IP addresses or internal networks to limit exposure.
  • Enforce strong, non‑default administrative passwords and enable two‑factor authentication if the device supports it; monitor logs for abnormal backup requests.

Generated by OpenCVE AI on August 24, 2026 at 19:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 24 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Description Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the webBackupAction function. The vulnerability is caused by repeated string concatenation of the pathN, valueN, key, and option fields into fixed-size stack buffers without total length checks. A remote attacker can trigger this vulnerability via crafted input, causing a denial of service or potentially executing arbitrary commands. Exploitation requires valid administrative credentials for the device's web management interface.
Title DrayTek VigorSwitch Multiple Models Buffer Overflow via webBackupAction
First Time appeared Draytek
Draytek vigorswitch Fx2120 Firmware
Draytek vigorswitch G1282 Firmware
Draytek vigorswitch G2100 Firmware
Draytek vigorswitch G2121 Firmware
Draytek vigorswitch G2280x Firmware
Draytek vigorswitch G2540xs Firmware
Draytek vigorswitch P1282 Firmware
Draytek vigorswitch P2100 Firmware
Draytek vigorswitch P2280x Firmware
Draytek vigorswitch P2540xs Firmware
Draytek vigorswitch Pq2121x Firmware
Draytek vigorswitch Pq2200xb Firmware
Draytek vigorswitch Q2121x Firmware
Draytek vigorswitch Q2200x Firmware
Weaknesses CWE-120
CPEs cpe:2.3:o:draytek:vigorswitch_fx2120_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:draytek:vigorswitch_g1282_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:draytek:vigorswitch_g2100_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:draytek:vigorswitch_g2121_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:draytek:vigorswitch_g2280x_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:draytek:vigorswitch_g2540xs_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:draytek:vigorswitch_p1282_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:draytek:vigorswitch_p2100_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:draytek:vigorswitch_p2280x_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:draytek:vigorswitch_p2540xs_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:draytek:vigorswitch_pq2121x_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:draytek:vigorswitch_pq2200xb_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:draytek:vigorswitch_q2121x_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:draytek:vigorswitch_q2200x_firmware:*:*:*:*:*:*:*:*
Vendors & Products Draytek
Draytek vigorswitch Fx2120 Firmware
Draytek vigorswitch G1282 Firmware
Draytek vigorswitch G2100 Firmware
Draytek vigorswitch G2121 Firmware
Draytek vigorswitch G2280x Firmware
Draytek vigorswitch G2540xs Firmware
Draytek vigorswitch P1282 Firmware
Draytek vigorswitch P2100 Firmware
Draytek vigorswitch P2280x Firmware
Draytek vigorswitch P2540xs Firmware
Draytek vigorswitch Pq2121x Firmware
Draytek vigorswitch Pq2200xb Firmware
Draytek vigorswitch Q2121x Firmware
Draytek vigorswitch Q2200x Firmware
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Draytek Vigorswitch Fx2120 Firmware Vigorswitch G1282 Firmware Vigorswitch G2100 Firmware Vigorswitch G2121 Firmware Vigorswitch G2280x Firmware Vigorswitch G2540xs Firmware Vigorswitch P1282 Firmware Vigorswitch P2100 Firmware Vigorswitch P2280x Firmware Vigorswitch P2540xs Firmware Vigorswitch Pq2121x Firmware Vigorswitch Pq2200xb Firmware Vigorswitch Q2121x Firmware Vigorswitch Q2200x Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-08-24T18:14:02.008Z

Reserved: 2026-08-08T16:37:44.519Z

Link: CVE-2026-71935

cve-icon Vulnrichment

Updated: 2026-08-24T18:13:54.730Z

cve-icon NVD

Status : Deferred

Published: 2026-08-24T18:17:18.490

Modified: 2026-08-26T17:08:22.300

Link: CVE-2026-71935

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T19:45:03Z

Weaknesses
  • CWE-120

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')