Draytek
Draytek Vigorswitch: vulnerabilidades y CVE
Draytek Vigorswitch tiene 29 vulnerabilidades publicadas, 29 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE29
Últimos 12 meses29
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-71943 | Alta (8.6) | 2.3% | — | 24 ago 2026 | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setDevNet function. The vulnerability is caused by insufficient filtering of the username and password fields before command… |
| CVE-2026-71942 | Alta (8.6) | 0.68% | — | 24 ago 2026 | Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the mail_mailalert function. The vulnerability is caused by concatenating multiple smtpReceiver email addresses into a fixed-size buffer… |
| CVE-2026-71941 | Alta (8.6) | 0.68% | — | 24 ago 2026 | Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the diag_logmail function. The vulnerability is caused by concatenating multiple smtpReceiver email addresses into a fixed-size buffer… |
| CVE-2026-71940 | Alta (8.6) | 0.68% | — | 24 ago 2026 | Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the acl_general_setup Edit ACE function. The vulnerability is caused by copying the name field into a fixed-size buffer without length… |
| CVE-2026-71939 | Alta (8.6) | 0.68% | — | 24 ago 2026 | Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the acl_general_setup Add ACE function. The vulnerability is caused by copying the name field into a fixed-size buffer without length… |
| CVE-2026-71938 | Alta (8.6) | 0.68% | — | 24 ago 2026 | Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the switch_lan_gvrp function. The vulnerability is caused by unsafe copying of the portList field into an undersized buffer. A remote… |
| CVE-2026-71937 | Alta (8.6) | 0.68% | — | 24 ago 2026 | Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the poe_schedule_profile function. The vulnerability is caused by repeated concatenation of the start_date, start_time, duration_time,… |
| CVE-2026-71936 | Alta (8.6) | 0.68% | — | 24 ago 2026 | Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the sysreboot function. The vulnerability is caused by unsafe concatenation of split valueN data into a fixed-size buffer. A remote attacker… |
| CVE-2026-71935 | Alta (8.6) | 0.68% | — | 24 ago 2026 | Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the webBackupAction function. The vulnerability is caused by repeated string concatenation of the pathN, valueN, key, and option fields into… |
| CVE-2026-71934 | Alta (8.6) | 0.68% | — | 24 ago 2026 | Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the pingtrace function. The vulnerability is caused by missing length checks when the host, count, and interval fields are concatenated into… |
| CVE-2026-71933 | Alta (8.8) | 0.55% | — | 24 ago 2026 | Multiple DrayTek VigorSwitch models contain unauthorized operation vulnerabilities in multiple syslog functions. The vulnerability is caused by missing authorization checks. A remote attacker can trigger these… |
| CVE-2026-71932 | Media (6.9) | 1.0% | — | 24 ago 2026 | Multiple DrayTek VigorSwitch models contain a directory traversal vulnerability in the getSyslogFile function. The vulnerability is caused by insufficient validation of the option field. A remote attacker can trigger… |
| CVE-2026-71931 | Alta (8.6) | 1.8% | — | 24 ago 2026 | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the tftp_upgrade function. The vulnerability is caused by insufficient filtering before the filename field is concatenated into a command.… |
| CVE-2026-71930 | Alta (8.6) | 2.3% | — | 24 ago 2026 | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setTime function. The vulnerability is caused by insufficient filtering of the username and password fields before command execution.… |
| CVE-2026-71929 | Alta (8.6) | 2.3% | — | 24 ago 2026 | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setDevProto function. The vulnerability is caused by insufficient filtering of the username and password fields before command… |
| CVE-2026-71928 | Alta (8.6) | 2.3% | — | 24 ago 2026 | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the fdftDevice function. The vulnerability is caused by insufficient filtering of the username and password fields before command… |
| CVE-2026-71927 | Alta (8.6) | 2.3% | — | 24 ago 2026 | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the rebDevice function. The vulnerability is caused by insufficient filtering of the username and password fields before command… |
| CVE-2026-71926 | Alta (8.6) | 2.3% | — | 24 ago 2026 | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setDevice function. The vulnerability is caused by insufficient sanitization of the username, password, and location fields before… |
| CVE-2026-71925 | Alta (8.6) | 2.3% | — | 24 ago 2026 | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the getDetail function. The vulnerability is caused by insufficient filtering of the username and password fields before command… |
| CVE-2026-71924 | Alta (8.6) | 2.3% | — | 24 ago 2026 | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the getVid function. The vulnerability is caused by insufficient filtering of the username and password fields before command execution. A… |
| CVE-2026-71923 | Alta (8.6) | 2.3% | — | 24 ago 2026 | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the auth_set function. The vulnerability is caused by insufficient filtering of the username and password fields before command execution.… |
| CVE-2026-71922 | Alta (8.7) | 0.69% | — | 24 ago 2026 | Multiple DrayTek VigorSwitch models contain a pre-authentication null pointer dereference vulnerability in the setget.cgi interface. The vulnerability is caused by missing validation when the pass field is absent. A… |
| CVE-2026-71921 | Crítica (9.3) | 2.8% | — | 24 ago 2026 | Multiple DrayTek VigorSwitch models contain a pre-authentication command injection vulnerability in the setget.cgi interface. The vulnerability is caused by insufficient filtering of the pass field before command… |
| CVE-2026-71920 | Media (6.9) | 0.56% | — | 24 ago 2026 | Multiple DrayTek VigorSwitch models contain a null pointer dereference vulnerability in the formlogout function. The vulnerability is caused by missing checks for an empty or absent Cookie header before string handling.… |
| CVE-2026-71919 | Alta (8.6) | 2.3% | — | 24 ago 2026 | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the sysreboot function. The vulnerability is caused by insufficient filtering of the config, act, pathN, and valueN fields before command… |
| CVE-2026-71918 | Alta (8.6) | 2.3% | — | 24 ago 2026 | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the webBackupAction function. The vulnerability is caused by insufficient filtering of the option, key, pw_encode, pathN, and valueN… |
| CVE-2026-71917 | Alta (8.6) | 2.3% | — | 24 ago 2026 | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the pingtrace function. The vulnerability is caused by insufficient validation of the host field before command execution. A remote… |
| CVE-2026-71916 | Alta (8.6) | 1.8% | — | 24 ago 2026 | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the commandTable function. The vulnerability is caused by incomplete filtering of dangerous characters such as backticks, newline… |
| CVE-2026-71915 | Alta (8.6) | 2.3% | — | 24 ago 2026 | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the jsonstatus function. The vulnerability is caused by insufficient filtering of the usescript, usefile, and option fields before command… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.