Impact
The vulnerability is a buffer overflow in the poe_schedule_profile function caused by concatenating several time‑related fields into fixed-size buffers without length checks. An attacker with valid administrative credentials to the device’s web management interface can supply crafted input to trigger the overflow, resulting in a denial of service or, more critically, the execution of arbitrary commands on the switch.
Affected Systems
Affected devices are DrayTek VigorSwitch models FX2120, G1280, G1282, G2100, G2121, G2280x, G2282x, G2540x, G2540xs, G2542x, P1280, P1281x, P1282, P2100, P2121, P2280x, P2282x, P2540x, P2540xs, P2542x, P2542xh, PQ2121x, PQ2200xb, PQ2300xb, PX2060, Q2121x, Q2200x, and Q2300x.
Risk and Exploitability
The CVSS score of 8.6 reflects a high‑severity vulnerability. While EPSS data is not available, the requirement of administrative credentials means that the attack surface is limited to devices with exposed web interfaces and active management accounts. The issue is not currently listed in the CISA KEV catalog, but the impact and lack of input validation in a security‑critical module warrant prompt remediation.
OpenCVE Enrichment