Sceawere

Vulnerability Detail

CVE-2026-71905UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

DrayTek VigorAP Command Injection Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.2
Creation Date
4h ago
Vendor
DrayTek Corporation
Product
VigorAP 918R
Attack Type
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Multiple DrayTek VigorAP models contain a command injection vulnerability in the ExportSettings function. The vulnerability is caused by insufficient filtering of the backupkey, backuptype, and realtime fields before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administrative credentials for the device's web management interface.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.2",
  "pubDate": "2026-08-24T18:17:01.890Z",
  "pubdate": "2026-08-24T18:17:01.890Z",
  "executiveSummary": "Multiple DrayTek VigorAP models suffer from a critical command injection vulnerability located within the ExportSettings function of the web management interface. The flaw stems from insufficient input sanitization and filtering applied to specific parameters, namely backupkey, backuptype, and realtime, prior to passing them into a command execution context. Successful exploitation of this security defect allows a remote attacker to execute arbitrary system commands with root privileges directly on the underlying operating system of the target device. The primary risk implication includes total compromise of the affected network access point, potential lateral movement into connected network segments, interception of sensitive data, and persistent unauthorized access. Although the attack grants high-privilege remote code execution capabilities, exploitation specifically requires the attacker to possess valid administrative credentials to successfully authenticate against the device's web management interface. Given the necessity of administrative access, the vulnerability represents a severe post-authentication risk that undermines the fundamental trust boundary of the device's administrative plane.",
  "technicalDetails": "The vulnerability resides in the ExportSettings function implemented within the web management interface of multiple DrayTek VigorAP models. The vulnerable component fails to adequately validate, sanitize, or escape user-supplied input data associated with the backupkey, backuptype, and realtime parameters before the application constructs and executes underlying system commands. When a remote attacker submits specially crafted, malicious payloads injected into these parameters via HTTP requests, the insecure application logic incorporates the untrusted input directly into a system shell execution routine. Because the affected binary executes these routines with elevated privileges, the successful injection results in arbitrary command execution running under the security context of the root user.\nThe exploitation method follows a specific attack flow. First, the remote attacker must authenticate to the device's web management interface using valid administrative credentials. Once authentication is established and session cookies or tokens are acquired, the attacker crafts a malicious HTTP request targeting the ExportSettings function. This crafted request embeds shell metacharacters and arbitrary system commands within the vulnerable backupkey, backuptype, or realtime fields. Upon receiving the HTTP request, the vulnerable firmware processes the input without proper sanitization, appending the malicious payload directly to the command execution string. The operating system shell subsequently interprets and executes the injected commands with root privileges. This grants the attacker the ability to manipulate system files, deploy persistent backdoors, alter network configurations, or utilize the compromised access point as a pivot point for further network penetration."
}
CVE-2026-71905: DrayTek VigorAP Command Injection Vulnerability (HIGH Severity, CVSS: 7.2) - Sceawere