Sceawere

Vulnerability Detail

CVE-2026-71908UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

DrayTek VigorAP Command Injection Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.2
Creation Date
4h ago
Vendor
DrayTek Corporation
Product
VigorAP 918R
Attack Type
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Multiple DrayTek VigorAP models contain a command injection vulnerability in the mesh_start_speed_test function. The vulnerability is caused by insufficient sanitization of the meshdevice_index and meshdevice_ip fields before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administrative credentials for the device's web management interface.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.2",
  "pubDate": "2026-08-24T18:17:02.420Z",
  "pubdate": "2026-08-24T18:17:02.420Z",
  "executiveSummary": "Multiple DrayTek VigorAP models suffer from a remote command injection vulnerability residing within the mesh_start_speed_test function.\nThe vulnerability stems from the inadequate sanitization and filtering of user-supplied input parameters, specifically the meshdevice_index and meshdevice_ip fields, prior to passing them into underlying system command execution routines.\nAn authenticated remote attacker possessing valid administrative credentials for the web management interface can exploit this security flaw by supplying maliciously crafted input parameters.\nSuccessful exploitation of this vulnerability results in the execution of arbitrary system commands with root privileges, granting the attacker total administrative control over the underlying operating system.\nThis introduces severe risk implications, including potential complete system compromise, unauthorized lateral movement across the network, interception of sensitive data, and persistent persistence establishment on affected wireless access point devices.\nMitigation requires restricting administrative access, applying vendor-supplied firmware updates if available, and monitoring administrative sessions for anomalous command execution patterns.",
  "technicalDetails": "The vulnerability is classified as an OS command injection flaw located in the mesh_start_speed_test function of multiple DrayTek VigorAP models.\nThe root cause of the vulnerability is the direct concatenation or insecure interpolation of input parameters derived from the web management interface into shell execution functions without proper lexical analysis, escaping, or strict input validation.\nSpecifically, the vulnerable input vectors are the meshdevice_index and meshdevice_ip fields, which fail to validate expected data formats such as valid IP address syntax or strict integer ranges.\nThe attack flow begins when an authenticated remote attacker sends a specifically crafted HTTP request targeting the web management interface, containing malicious shell metacharacters injected into the meshdevice_index or meshdevice_ip parameters.\nBecause the application passes these unsanitized parameters directly to the underlying operating system shell via the mesh_start_speed_test function, the shell interprets the injected metacharacters as command separators or operators.\nThe network exposure involves the device's administrative web management interface, which is typically accessible over HTTP or HTTPS from the local network or potentially exposed externally if misconfigured.\nAuthentication requirements dictate that the attacker must first obtain valid administrative credentials to successfully authenticate to the web management interface before the vulnerable function can be invoked.\nThe privilege requirements for exploitation are administrative credentials, but the resultant post-exploitation impact executes arbitrary payloads with root privileges, allowing the attacker to bypass normal security controls entirely.\nPayload behavior during successful exploitation includes executing arbitrary system binaries, modifying system configurations, deploying persistent backdoors, or leveraging the compromised access point as a pivot point for further internal network reconnaissance and attacks."
}
CVE-2026-71908: DrayTek VigorAP Command Injection Vulnerability (HIGH Severity, CVSS: 7.2) - Sceawere