Impact
The vulnerability is a classic buffer overflow in the switch_lan_gvrp function, caused by unsafe copying of the portList field into an undersized buffer. An attacker who can send crafted input to the device's web management interface can trigger a denial of service or, potentially, execute arbitrary commands on the appliance. The flaw therefore threatens confidentiality, integrity, and availability of the network device, and could be a stepping stone to compromise the broader network if the device is misused.
Affected Systems
Multiple DrayTek VigorSwitch models, including FX2120, G1280, G1282, G2100, G2121, G2280x, G2282x, G2540x, G2540xs, G2542x, P1280, P1281x, P1282, P2100, P2121, P2280x, P2282x, P2540x, P2540xs, P2542x, P2542xh, PQ2121x, PQ2200xb, PQ2300xb, PX2060, Q2121x, Q2200x, and Q2300x. All firmware versions supporting the switch_lan_gvrp function are impacted; the specific patched versions are listed in DrayTek's security advisory.
Risk and Exploitability
The CVSS score of 8.6 indicates high severity. No EPSS score is available, so the current estimated likelihood of exploitation is unknown, but the vulnerability is active and can be triggered remotely with administrative credentials. The flaw is not listed in the CISA KEV catalog, yet its impact justifies urgent remediation. Attackers must authenticate to the web interface, so mitigation by restricting management access mitigates the threat.
OpenCVE Enrichment