Draytek
Draytek Vigorap: vulnerabilidades y CVE
Draytek Vigorap tiene 11 vulnerabilidades publicadas, 11 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE11
Últimos 12 meses11
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-71914 | Crítica (9.3) | 2.6% | — | 24 ago 2026 | Multiple DrayTek VigorAP models contain a command injection vulnerability in the dray_apm component. The vulnerability is caused by insufficient validation of UDP message content after START_SPEED_TEST before command… |
| CVE-2026-71913 | Alta (8.6) | 1.8% | — | 24 ago 2026 | Multiple DrayTek VigorAP models contain a command injection vulnerability in the upload_settings.cgi interface. The vulnerability is caused by insufficient filtering before the restorekey field is concatenated into a… |
| CVE-2026-71912 | Alta (8.6) | 0.68% | — | 24 ago 2026 | Multiple DrayTek VigorAP models contain a buffer overflow vulnerability in the apautotest function. The vulnerability is caused by missing length checks during memory copy operations involving the CMD6 field. A remote… |
| CVE-2026-71911 | Alta (8.6) | 0.68% | — | 24 ago 2026 | Multiple DrayTek VigorAP models contain a buffer overflow vulnerability in the setLan function. The vulnerability is caused by missing length checks during memory copy operations involving the lanVlanId0, lanIp, and… |
| CVE-2026-71910 | Alta (8.6) | 2.3% | — | 24 ago 2026 | Multiple DrayTek VigorAP models contain a command injection vulnerability in the apautotest function. The vulnerability is caused by insufficient validation of the CMD0, CMD3, and CMD6 fields before command execution. A… |
| CVE-2026-71909 | Alta (8.6) | 2.3% | — | 24 ago 2026 | Multiple DrayTek VigorAP models contain a command injection vulnerability in the InquierTime function. The vulnerability is caused by insufficient filtering of the time field before command execution. A remote attacker… |
| CVE-2026-71908 | Alta (8.6) | 2.3% | — | 24 ago 2026 | Multiple DrayTek VigorAP models contain a command injection vulnerability in the mesh_start_speed_test function. The vulnerability is caused by insufficient sanitization of the meshdevice_index and meshdevice_ip fields… |
| CVE-2026-71907 | Alta (8.6) | 2.3% | — | 24 ago 2026 | Multiple DrayTek VigorAP models contain a command injection vulnerability in the setcamset function. The vulnerability is caused by insufficient filtering of the selectSlaves field before command execution. A remote… |
| CVE-2026-71906 | Alta (8.6) | 2.3% | — | 24 ago 2026 | Multiple DrayTek VigorAP models contain a command injection vulnerability in the setLan function. The vulnerability is caused by insufficient validation of the lanIp and lanNetmask fields before command execution. A… |
| CVE-2026-71905 | Alta (8.6) | 2.3% | — | 24 ago 2026 | Multiple DrayTek VigorAP models contain a command injection vulnerability in the ExportSettings function. The vulnerability is caused by insufficient filtering of the backupkey, backuptype, and realtime fields before… |
| CVE-2026-71904 | Alta (8.6) | 1.8% | — | 24 ago 2026 | Multiple DrayTek VigorAP models contain a command injection vulnerability in the tr069TestInform function. The vulnerability is caused by insufficient filtering of dangerous characters before the event_code field is… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.