CVE-2026-71917
Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the pingtrace function. The vulnerability is caused by insufficient validation of the host field before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administrative credentials for the device's web management interface.
CVSS
- Versión: 4.0
- Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Puntuación base: 8.6
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 2.27%
- Percentil entre todas las CVEs puntuadas: 82
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1210Exploitation of Remote Serviceslateral movement85 % - Impacto principal
T1059Command and Scripting Interpreterexecution90 % - Impacto secundario
T1068Exploitation for Privilege Escalationprivilege escalation75 %
Vector CVSS de red con PR:H (requiere autenticación administrativa). CWE-78 (command injection) permite ejecución arbitraria de comandos con privilegios root. La inyección de comandos en función remota expuesta (pingtrace) en interfaz web de gestión es T1210 con impacto T1059 (ejecución de comandos)
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
CWE
- CWE-78
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-71917",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-71917",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2026-08-24T18:57:34.863789Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "disclosure@vulncheck.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.2,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "HIGH",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 1.2
}
],
"cvssMetricV40": [
{
"type": "Secondary",
"source": "disclosure@vulncheck.com",
"cvssData": {
"Safety": "NOT_DEFINED",
"version": "4.0",
"Recovery": "NOT_DEFINED",
"baseScore": 8.6,
"Automatable": "NOT_DEFINED",
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"exploitMaturity": "NOT_DEFINED",
"providerUrgency": "NOT_DEFINED",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"privilegesRequired": "HIGH",
"subIntegrityImpact": "NONE",
"vulnIntegrityImpact": "HIGH",
"integrityRequirement": "NOT_DEFINED",
"modifiedAttackVector": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"vulnAvailabilityImpact": "HIGH",
"availabilityRequirement": "NOT_DEFINED",
"modifiedUserInteraction": "NOT_DEFINED",
"modifiedAttackComplexity": "NOT_DEFINED",
"subConfidentialityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"confidentialityRequirement": "NOT_DEFINED",
"modifiedAttackRequirements": "NOT_DEFINED",
"modifiedPrivilegesRequired": "NOT_DEFINED",
"modifiedSubIntegrityImpact": "NOT_DEFINED",
"modifiedVulnIntegrityImpact": "NOT_DEFINED",
"vulnerabilityResponseEffort": "NOT_DEFINED",
"modifiedSubAvailabilityImpact": "NOT_DEFINED",
"modifiedVulnAvailabilityImpact": "NOT_DEFINED",
"modifiedSubConfidentialityImpact": "NOT_DEFINED",
"modifiedVulnConfidentialityImpact": "NOT_DEFINED"
}
}
]
},
"affected": [
{
"source": "disclosure@vulncheck.com",
"affectedData": [
{
"vendor": "DrayTek Corporation",
"product": "VigorSwitch G2540xs",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "3.9.10",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "DrayTek Corporation",
"product": "VigorSwitch P2540xs",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "3.9.10",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "DrayTek Corporation",
"product": "VigorSwitch FX2120",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "3.9.10",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "DrayTek Corporation",
"product": "VigorSwitch G2282x",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "2.10.6",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "DrayTek Corporation",
"product": "VigorSwitch P2282x",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "2.10.6",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "DrayTek Corporation",
"product": "VigorSwitch Q2300x",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "2.10.7",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "DrayTek Corporation",
"product": "VigorSwitch PQ2300xb",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "2.10.7",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "DrayTek Corporation",
"product": "VigorSwitch G2542x",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "3.10.6",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "DrayTek Corporation",
"product": "VigorSwitch P2542x",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "3.10.6",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "DrayTek Corporation",
"product": "VigorSwitch P2542xh",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "3.10.6",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "DrayTek Corporation",
"product": "VigorSwitch PX2060",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "2.9.10",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "DrayTek Corporation",
"product": "VigorSwitch G1280",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "2.9.10",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "DrayTek Corporation",
"product": "VigorSwitch P1280",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "2.9.10",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "DrayTek Corporation",
"product": "VigorSwitch P1281x",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "2.9.10",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "DrayTek Corporation",
"product": "VigorSwitch G1282",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "2.9.10",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "DrayTek Corporation",
"product": "VigorSwitch P1282",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "2.9.10",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "DrayTek Corporation",
"product": "VigorSwitch G2121",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "2.9.10",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "DrayTek Corporation",
"product": "VigorSwitch P2121",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "2.9.10",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "DrayTek Corporation",
"product": "VigorSwitch PQ2121x",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "2.9.10",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "DrayTek Corporation",
"product": "VigorSwitch Q2121x",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "2.9.10",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "DrayTek Corporation",
"product": "VigorSwitch G2280x",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "2.9.10",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "DrayTek Corporation",
"product": "VigorSwitch P2280x",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "2.9.10",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "DrayTek Corporation",
"product": "VigorSwitch Q2200x",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "2.9.10",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "DrayTek Corporation",
"product": "VigorSwitch PQ2200xb",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "2.9.10",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "DrayTek Corporation",
"product": "VigorSwitch G2100",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "2.9.10",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "DrayTek Corporation",
"product": "VigorSwitch P2100",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "2.9.10",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "DrayTek Corporation",
"product": "VigorSwitch G2540x",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "2.9.10",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "DrayTek Corporation",
"product": "VigorSwitch P2540x",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "2.9.10",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2026-08-24T18:17:06.153",
"references": [
{
"url": "https://www.draytek.com/about/security-advisory/multiple-vulnerabilities-in-vigorswitch-series-august-2026/",
"source": "disclosure@vulncheck.com"
},
{
"url": "https://www.vulncheck.com/advisories/draytek-vigorswitch-multiple-models-os-command-injection-via-pingtrace",
"source": "disclosure@vulncheck.com"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "disclosure@vulncheck.com",
"description": [
{
"lang": "en",
"value": "CWE-78"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the pingtrace function. The vulnerability is caused by insufficient validation of the host field before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administrative credentials for the device's web management interface."
}
],
"lastModified": "2026-08-26T17:10:09.810",
"sourceIdentifier": "disclosure@vulncheck.com"
}