Impact
The vulnerability arises from insufficient filtering of user name and password inputs in the setDevNet function on numerous DrayTek VigorSwitch device series. An attacker who can craft a payload containing shell metacharacters is able to execute arbitrary OS commands with root privileges when the inputs are processed. This allows full compromise of the device, enabling an attacker to exfiltrate data, modify configurations, or establish persistent footholds.
Affected Systems
Affected devices include the VigorSwitch FX2120, G1280, G1282, G2100, G2121, G2280x, G2282x, G2540x, G2540xs, G2542x, P1280, P1281x, P1282, P2100, P2121, P2280x, P2282x, P2540x, P2540xs, P2542x, P2542xh, PQ2121x, PQ2200xb, PQ2300xb, PX2060, Q2121x, Q2200x, and Q2300x models. Versions and firmware revisions are not specified beyond the stated models; the issue is present across multiple firmware builds.
Risk and Exploitability
The assigned CVSS score of 8.6 indicates high severity, and the EPSS score indicates a 3% exploitation probability, but the absence of a KEV flag does not reduce the risk if credentials are compromised. Exploitation requires valid administrative credentials for the web management interface, so internal attackers or attackers who obtain web admin credentials pose the greatest threat. Attackers could manually input commands via the login form or via automated scripts after credential theft. No public exploits have been documented yet, but the vulnerability is trivially exploitable with knowledge of the interface.
OpenCVE Enrichment