Sceawere

Vulnerability Detail

CVE-2026-71909UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

DrayTek VigorAP Command Injection Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.2
Creation Date
4h ago
Vendor
DrayTek Corporation
Product
VigorAP 918R
Attack Type
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Multiple DrayTek VigorAP models contain a command injection vulnerability in the InquierTime function. The vulnerability is caused by insufficient filtering of the time field before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administrative credentials for the device's web management interface.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.2",
  "pubDate": "2026-08-24T18:17:02.593Z",
  "pubdate": "2026-08-24T18:17:02.593Z",
  "executiveSummary": "A command injection vulnerability exists within multiple DrayTek VigorAP models, specifically residing in the InquierTime function of the device firmware. This security flaw stems from the failure to adequately sanitize and filter input parameters supplied to the time field before they are processed and passed to the underlying operating system for execution.\nThe primary impact of this vulnerability is the complete compromise of the affected hardware appliance. A remote threat actor who successfully exploits this flaw can execute arbitrary system commands directly on the underlying host operating system.\nExploitation of this vulnerability requires the attacker to possess valid administrative credentials to successfully authenticate against the device's web management interface. Despite this authentication prerequisite, the risk implications remain severe because successful exploitation yields root-level privileges, granting the attacker unrestricted control over the affected network device.\nAffected systems are limited to the specified DrayTek VigorAP models implementing the vulnerable InquierTime function within their web administration architecture. Organizations utilizing these wireless access points face potential risks including complete device takeover, interception or manipulation of wireless network traffic, and potential pivoting into internal network segments if the compromised access point is leveraged as a foothold.",
  "technicalDetails": "The vulnerability is classified as an OS command injection flaw located within the InquierTime function of multiple DrayTek VigorAP models. The root cause of the vulnerability is insufficient input validation and improper sanitization of the time field. When the application processes user-supplied data intended for this field, it fails to strip or escape shell metacharacters before passing the string to a system execution sink.\nThe vulnerable component is the web management interface handling administrative backend routines associated with time configuration and inquiry requests. The network exposure is remote, accessible via the HTTP or HTTPS management services exposed by the device, though exploitation strictly requires valid administrative credentials to bypass authentication boundaries.\nThe attack flow proceeds in a sequential manner. First, the remote attacker authenticates to the device's web management interface using acquired or compromised administrative credentials. Second, the attacker crafts a malicious HTTP request targeting the InquierTime function, injecting arbitrary system command syntax into the vulnerable time parameter alongside standard input. Third, the application receives the crafted payload and improperly passes the unsanitized string into a system shell execution context.\nUpon execution, the underlying operating system interprets the injected shell metacharacters and executes the attacker's payload with root privileges. Because the web management daemon typically operates with elevated system rights, the resulting command execution inherits root-level privileges. Post-exploitation impact includes full administrative ownership of the appliance, potential firmware tampering, persistent backdoor installation, denial of service through system resource exhaustion, and unauthorized inspection of local network traffic traversing the VigorAP device."
}
CVE-2026-71909: DrayTek VigorAP Command Injection Vulnerability (HIGH Severity, CVSS: 7.2) - Sceawere