Impact
A buffer overflow exists in the acl_general_setup Add ACE routine of multiple DrayTek VigorSwitch models. The bug arises when the code copies an ACE name field into a fixed‑size buffer without validating its length. If an attacker crafts input for the web management interface while holding administrative credentials, the overflow can crash the device or, in the worst case, allow the execution of arbitrary commands on the switch stack. The vulnerability is classified as high severity with a CVSS score of 8.6.
Affected Systems
The issue affects a range of DrayTek VigorSwitch devices, including FX2120, G1280, G1282, G2100, G2121, G2280x, G2282x, G2540x, G2540xs, G2542x, P1280, P1281x, P1282, P2100, P2121, P2280x, P2282x, P2540x, P2540xs, P2542x, P2542xh, PQ2121x, PQ2200xb, PQ2300xb, PX2060, Q2121x, Q2200x, and Q2300x. Firmware information is not supplied, so all firmware builds for each model are potentially vulnerable.
Risk and Exploitability
The CVSS rating of 8.6 indicates a high severity vulnerability. Although the EPSS score is not available, exploitation requires authenticated access to the device’s web console, limiting the attack surface to users who have administrative privileges or attackers who have compromised the network. The vulnerability is not listed in CISA’s KEV catalog; however, its high severity and wide product coverage combine to keep the overall risk significant until the device is patched.
OpenCVE Enrichment