Impact
The vulnerability is a buffer overflow in the sysreboot function caused by unsafe concatenation of split valueN data into a fixed-size buffer. A remote attacker with valid administrative credentials can trigger the vulnerability via crafted input through the device's web management interface, leading to a denial of service or potentially executing arbitrary commands. The weakness is classified as CWE-120.
Affected Systems
Affected systems include a broad range of DrayTek VigorSwitch models: FX2120, G1280, G1282, G2100, G2121, G2280x, G2282x, G2540x, G2540xs, G2542x, P1280, P1281x, P1282, P2100, P2121, P2280x, P2282x, P2540x, P2540xs, P2542x, P2542xh, PQ2121x, PQ2200xb, PQ2300xb, PX2060, Q2121x, Q2200x, and Q2300x. All models run the affected firmware versions referenced in the advisory.
Risk and Exploitability
The CVSS score of 8.6 categorizes this flaw as high severity. EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires authenticated access to the web management interface, making the risk significant for environments where credentials are known or weak. Once authenticated, an attacker can deliver malicious payloads that trigger the buffer overflow, potentially gaining arbitrary command execution on the device. Therefore, the likelihood of exploitation is elevated in enterprises with remote or locally accessed management interfaces that are not properly secured.
OpenCVE Enrichment