Impact
A buffer overflow exists in the mail_mailalert function of multiple DrayTek VigorSwitch models, caused by concatenating smtpReceiver email addresses into a fixed‑size buffer without bounds checking. An attacker who can interact with the web‑based management interface and supply crafted input can trigger the overflow, potentially leading to a denial of service or execution of arbitrary commands on the device.
Affected Systems
The vulnerability affects a wide range of DrayTek VigorSwitch devices, including FX2120, G1280, G1282, G2100, G2121, G2280x, G2282x, G2540x, G2542x, P1280, P1281x, P1282, P2100, P2121, P2280x, P2282x, P2540x, P2540xs, P2542x, P2542xh, PQ2121x, PQ2200xb, PQ2300xb, PX2060, Q2121x, Q2200x, and Q2300x.
Risk and Exploitability
The CVSS score of 8.6 indicates a high impact, and the exploitation path requires valid administrative credentials to the device’s web interface. While the EPSS score is not currently available and the vulnerability is not listed in the CISA KEV catalog, the high severity combined with the need for privileged access implies significant risk for organizations that expose these devices to remote administration.
OpenCVE Enrichment