Impact
A buffer overflow occurs when the acl_general_setup Edit ACE function copies a user-supplied name field into a fixed-size buffer without validating its length. The vulnerability is specifically a CWE‑120 flaw. If an attacker successfully triggers the overflow they can either crash the web management service for a denial of service or, at a minimum, inject and execute arbitrary commands on the device.
Affected Systems
The issue affects a wide range of DrayTek VigorSwitch devices, including the FX2120, G1280, G1282, G2100, G2121, G2280x, G2282x, G2540x, G2540xs, G2542x, P1280, P1281x, P1282, P2100, P2121, P2280x, P2282x, P2540x, P2540xs, P2542x, P2542xh, PQ2121x, PQ2200xb, PQ2300xb, PX2060, Q2121x, Q2200x, and Q2300x. No specific firmware versions were listed as affected, so all current releases should be considered vulnerable until patches are applied.
Risk and Exploitability
The CVSS score of 8.6 classifies the flaw as high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, indicating limited publicly known exploitation. However, the vulnerability requires valid administrative credentials to the device's web interface, meaning only authenticated users can attempt exploitation. The likely attack vector is a remote attacker submitting crafted input through the web GUI to trigger a buffer overflow, leading to service disruption or code execution.
OpenCVE Enrichment