Impact
A buffer overflow in the diag_logmail function occurs when multiple smtpReceiver email addresses are concatenated into a fixed-size buffer without bounds checking. An attacker who can send crafted input via the web management interface and has valid administrative credentials can trigger the overflow, potentially executing arbitrary commands or crashing the device. This flaw directly compromises the device’s integrity and availability, allowing remote control or denial of service.
Affected Systems
The vulnerability affects a broad set of DrayTek VigorSwitch routers, including FX2120, G1280, G1282, G2100, G2121, G2280x, G2282x, G2540x, G2540xs, G2542x, P1280, P1281x, P1282, P2100, P2121, P2280x, P2282x, P2540x, P2540xs, P2542x, P2542xh, PQ2121x, PQ2200xb, PQ2300xb, PX2060, Q2121x, Q2200x, and Q2300x. Firmware version details are not provided, so all deployed firmware on these models may be vulnerable.
Risk and Exploitability
The CVSS score of 8.6 classifies this issue as high severity. The lack of an EPSS score means the current exploitation prevalence is unclear. Exploitation requires valid admin credentials to the web interface, which may be limited but still constitutes a significant risk for devices exposed to external networks. Once executed, the exploit can crash the device or run arbitrary commands, potentially leading to full system compromise. Consequently, the overall risk is high, especially for remotely managed devices left open to untrusted hosts.
OpenCVE Enrichment