Description
Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the mail_mailalert function. The vulnerability is caused by concatenating multiple smtpReceiver email addresses into a fixed-size buffer without checking the remaining buffer size. A remote attacker can trigger this vulnerability via crafted input, causing a denial of service or potentially executing arbitrary commands. Exploitation requires valid administrative credentials for the device's web management interface.
Published: 2026-08-24
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution or Denial of Service
Action: Apply Patch
AI Analysis

Impact

A buffer overflow exists in the mail_mailalert function of multiple DrayTek VigorSwitch models, caused by concatenating smtpReceiver email addresses into a fixed‑size buffer without bounds checking. An attacker who can interact with the web‑based management interface and supply crafted input can trigger the overflow, potentially leading to a denial of service or execution of arbitrary commands on the device.

Affected Systems

The vulnerability affects a wide range of DrayTek VigorSwitch devices, including FX2120, G1280, G1282, G2100, G2121, G2280x, G2282x, G2540x, G2542x, P1280, P1281x, P1282, P2100, P2121, P2280x, P2282x, P2540x, P2540xs, P2542x, P2542xh, PQ2121x, PQ2200xb, PQ2300xb, PX2060, Q2121x, Q2200x, and Q2300x.

Risk and Exploitability

The CVSS score of 8.6 indicates a high impact, and the exploitation path requires valid administrative credentials to the device’s web interface. While the EPSS score is not currently available and the vulnerability is not listed in the CISA KEV catalog, the high severity combined with the need for privileged access implies significant risk for organizations that expose these devices to remote administration.

Generated by OpenCVE AI on August 24, 2026 at 19:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the device firmware to the latest version released by DrayTek that fixes the mail_mailalert buffer‑overflow flaw.
  • If a firmware patch is not yet available, disable or restrict remote access to the web‑based management interface by applying network firewall rules or VPN restrictions.
  • Disabling the mail alert functionality or removing smtpReceiver entries from the device configuration will eliminate the vulnerable code path and reduce the attack surface.

Generated by OpenCVE AI on August 24, 2026 at 19:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 24 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Description Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the mail_mailalert function. The vulnerability is caused by concatenating multiple smtpReceiver email addresses into a fixed-size buffer without checking the remaining buffer size. A remote attacker can trigger this vulnerability via crafted input, causing a denial of service or potentially executing arbitrary commands. Exploitation requires valid administrative credentials for the device's web management interface.
Title DrayTek VigorSwitch Multiple Models Buffer Overflow via mail_mailalert
First Time appeared Draytek
Draytek vigorswitch Fx2120 Firmware
Draytek vigorswitch G1282 Firmware
Draytek vigorswitch G2100 Firmware
Draytek vigorswitch G2121 Firmware
Draytek vigorswitch G2280x Firmware
Draytek vigorswitch G2540xs Firmware
Draytek vigorswitch P1282 Firmware
Draytek vigorswitch P2100 Firmware
Draytek vigorswitch P2280x Firmware
Draytek vigorswitch P2540xs Firmware
Draytek vigorswitch Pq2121x Firmware
Draytek vigorswitch Pq2200xb Firmware
Draytek vigorswitch Q2121x Firmware
Draytek vigorswitch Q2200x Firmware
Weaknesses CWE-120
CPEs cpe:2.3:o:draytek:vigorswitch_fx2120_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:draytek:vigorswitch_g1282_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:draytek:vigorswitch_g2100_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:draytek:vigorswitch_g2121_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:draytek:vigorswitch_g2280x_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:draytek:vigorswitch_g2540xs_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:draytek:vigorswitch_p1282_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:draytek:vigorswitch_p2100_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:draytek:vigorswitch_p2280x_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:draytek:vigorswitch_p2540xs_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:draytek:vigorswitch_pq2121x_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:draytek:vigorswitch_pq2200xb_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:draytek:vigorswitch_q2121x_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:draytek:vigorswitch_q2200x_firmware:*:*:*:*:*:*:*:*
Vendors & Products Draytek
Draytek vigorswitch Fx2120 Firmware
Draytek vigorswitch G1282 Firmware
Draytek vigorswitch G2100 Firmware
Draytek vigorswitch G2121 Firmware
Draytek vigorswitch G2280x Firmware
Draytek vigorswitch G2540xs Firmware
Draytek vigorswitch P1282 Firmware
Draytek vigorswitch P2100 Firmware
Draytek vigorswitch P2280x Firmware
Draytek vigorswitch P2540xs Firmware
Draytek vigorswitch Pq2121x Firmware
Draytek vigorswitch Pq2200xb Firmware
Draytek vigorswitch Q2121x Firmware
Draytek vigorswitch Q2200x Firmware
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Draytek Vigorswitch Fx2120 Firmware Vigorswitch G1282 Firmware Vigorswitch G2100 Firmware Vigorswitch G2121 Firmware Vigorswitch G2280x Firmware Vigorswitch G2540xs Firmware Vigorswitch P1282 Firmware Vigorswitch P2100 Firmware Vigorswitch P2280x Firmware Vigorswitch P2540xs Firmware Vigorswitch Pq2121x Firmware Vigorswitch Pq2200xb Firmware Vigorswitch Q2121x Firmware Vigorswitch Q2200x Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-08-24T18:38:01.010Z

Reserved: 2026-08-08T16:37:44.519Z

Link: CVE-2026-71942

cve-icon Vulnrichment

Updated: 2026-08-24T18:37:56.353Z

cve-icon NVD

Status : Deferred

Published: 2026-08-24T18:17:19.877

Modified: 2026-08-26T17:08:22.300

Link: CVE-2026-71942

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T19:15:04Z

Weaknesses
  • CWE-120

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')