« Volver al listado

Draytek

Draytek Vigorswitch: vulnerabilidades y CVE

Draytek Vigorswitch tiene 29 vulnerabilidades publicadas, 29 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE29
Últimos 12 meses29
Críticas1
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-71943Alta (8.6)2.3%—24 ago 2026
Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setDevNet function. The vulnerability is caused by insufficient filtering of the username and password fields before command…
CVE-2026-71942Alta (8.6)0.68%—24 ago 2026
Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the mail_mailalert function. The vulnerability is caused by concatenating multiple smtpReceiver email addresses into a fixed-size buffer…
CVE-2026-71941Alta (8.6)0.68%—24 ago 2026
Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the diag_logmail function. The vulnerability is caused by concatenating multiple smtpReceiver email addresses into a fixed-size buffer…
CVE-2026-71940Alta (8.6)0.68%—24 ago 2026
Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the acl_general_setup Edit ACE function. The vulnerability is caused by copying the name field into a fixed-size buffer without length…
CVE-2026-71939Alta (8.6)0.68%—24 ago 2026
Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the acl_general_setup Add ACE function. The vulnerability is caused by copying the name field into a fixed-size buffer without length…
CVE-2026-71938Alta (8.6)0.68%—24 ago 2026
Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the switch_lan_gvrp function. The vulnerability is caused by unsafe copying of the portList field into an undersized buffer. A remote…
CVE-2026-71937Alta (8.6)0.68%—24 ago 2026
Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the poe_schedule_profile function. The vulnerability is caused by repeated concatenation of the start_date, start_time, duration_time,…
CVE-2026-71936Alta (8.6)0.68%—24 ago 2026
Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the sysreboot function. The vulnerability is caused by unsafe concatenation of split valueN data into a fixed-size buffer. A remote attacker…
CVE-2026-71935Alta (8.6)0.68%—24 ago 2026
Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the webBackupAction function. The vulnerability is caused by repeated string concatenation of the pathN, valueN, key, and option fields into…
CVE-2026-71934Alta (8.6)0.68%—24 ago 2026
Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the pingtrace function. The vulnerability is caused by missing length checks when the host, count, and interval fields are concatenated into…
CVE-2026-71933Alta (8.8)0.55%—24 ago 2026
Multiple DrayTek VigorSwitch models contain unauthorized operation vulnerabilities in multiple syslog functions. The vulnerability is caused by missing authorization checks. A remote attacker can trigger these…
CVE-2026-71932Media (6.9)1.0%—24 ago 2026
Multiple DrayTek VigorSwitch models contain a directory traversal vulnerability in the getSyslogFile function. The vulnerability is caused by insufficient validation of the option field. A remote attacker can trigger…
CVE-2026-71931Alta (8.6)1.8%—24 ago 2026
Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the tftp_upgrade function. The vulnerability is caused by insufficient filtering before the filename field is concatenated into a command.…
CVE-2026-71930Alta (8.6)2.3%—24 ago 2026
Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setTime function. The vulnerability is caused by insufficient filtering of the username and password fields before command execution.…
CVE-2026-71929Alta (8.6)2.3%—24 ago 2026
Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setDevProto function. The vulnerability is caused by insufficient filtering of the username and password fields before command…
CVE-2026-71928Alta (8.6)2.3%—24 ago 2026
Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the fdftDevice function. The vulnerability is caused by insufficient filtering of the username and password fields before command…
CVE-2026-71927Alta (8.6)2.3%—24 ago 2026
Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the rebDevice function. The vulnerability is caused by insufficient filtering of the username and password fields before command…
CVE-2026-71926Alta (8.6)2.3%—24 ago 2026
Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setDevice function. The vulnerability is caused by insufficient sanitization of the username, password, and location fields before…
CVE-2026-71925Alta (8.6)2.3%—24 ago 2026
Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the getDetail function. The vulnerability is caused by insufficient filtering of the username and password fields before command…
CVE-2026-71924Alta (8.6)2.3%—24 ago 2026
Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the getVid function. The vulnerability is caused by insufficient filtering of the username and password fields before command execution. A…
CVE-2026-71923Alta (8.6)2.3%—24 ago 2026
Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the auth_set function. The vulnerability is caused by insufficient filtering of the username and password fields before command execution.…
CVE-2026-71922Alta (8.7)0.69%—24 ago 2026
Multiple DrayTek VigorSwitch models contain a pre-authentication null pointer dereference vulnerability in the setget.cgi interface. The vulnerability is caused by missing validation when the pass field is absent. A…
CVE-2026-71921Crítica (9.3)2.8%—24 ago 2026
Multiple DrayTek VigorSwitch models contain a pre-authentication command injection vulnerability in the setget.cgi interface. The vulnerability is caused by insufficient filtering of the pass field before command…
CVE-2026-71920Media (6.9)0.56%—24 ago 2026
Multiple DrayTek VigorSwitch models contain a null pointer dereference vulnerability in the formlogout function. The vulnerability is caused by missing checks for an empty or absent Cookie header before string handling.…
CVE-2026-71919Alta (8.6)2.3%—24 ago 2026
Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the sysreboot function. The vulnerability is caused by insufficient filtering of the config, act, pathN, and valueN fields before command…
CVE-2026-71918Alta (8.6)2.3%—24 ago 2026
Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the webBackupAction function. The vulnerability is caused by insufficient filtering of the option, key, pw_encode, pathN, and valueN…
CVE-2026-71917Alta (8.6)2.3%—24 ago 2026
Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the pingtrace function. The vulnerability is caused by insufficient validation of the host field before command execution. A remote…
CVE-2026-71916Alta (8.6)1.8%—24 ago 2026
Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the commandTable function. The vulnerability is caused by incomplete filtering of dangerous characters such as backticks, newline…
CVE-2026-71915Alta (8.6)2.3%—24 ago 2026
Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the jsonstatus function. The vulnerability is caused by insufficient filtering of the usescript, usefile, and option fields before command…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1059 Command and Scripting Interpreter25
  2. T1210 Exploitation of Remote Services24
  3. T1190 Exploit Public-Facing Application3
  4. T1499.004 Application or System Exploitation1
  5. T1565.001 Stored Data Manipulation1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Draytek