Sceawere

Vulnerability Detail

CVE-2026-71914UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

DrayTek VigorAP Command Injection Vulnerability

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.8
Creation Date
4h ago
Vendor
DrayTek Corporation
Product
VigorAP 918R
Attack Type
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Multiple DrayTek VigorAP models contain a command injection vulnerability in the dray_apm component. The vulnerability is caused by insufficient validation of UDP message content after START_SPEED_TEST before command execution. A remote attacker can trigger this vulnerability via a crafted message to execute arbitrary commands with root privileges.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.8",
  "pubDate": "2026-08-24T18:17:03.497Z",
  "pubdate": "2026-08-24T18:17:03.497Z",
  "executiveSummary": "Multiple DrayTek VigorAP models suffer from a critical remote command injection vulnerability residing within the dray_apm component. This security flaw stems from insufficient input validation and sanitization of UDP message content processed immediately following the START_SPEED_TEST command. An unauthenticated remote attacker capable of communicating with the vulnerable network service can exploit this weakness by transmitting a crafted UDP message containing malicious system commands. Successful exploitation results in arbitrary command execution with elevated root privileges, entirely compromising the confidentiality, integrity, and availability of the affected access point. The high severity of this vulnerability stems from the combination of root-level execution capabilities and the potential for remote exploitation over the network without requiring prior authentication or user interaction. Remediation requires applying official vendor patches as soon as they become available or restricting network access to vulnerable services.",
  "technicalDetails": "The vulnerability is localized within the dray_apm component running on multiple DrayTek VigorAP models. The root cause of the flaw is the lack of proper input validation and sanitization mechanisms applied to UDP message payloads received by the application. Specifically, when processing messages that follow the START_SPEED_TEST identifier, the component insecurely parses the incoming data stream and passes unsanitized portions of the UDP message content directly into system command execution functions.\nThe attack vector is network-based, allowing a remote attacker to interact directly with the vulnerable UDP service exposed by the device. To execute an attack, the malicious actor crafts a specialized UDP payload designed to break out of the intended data context and append arbitrary shell commands. This crafted payload is transmitted directly to the targeted DrayTek VigorAP model over the network.\nUpon receipt of the malicious UDP datagram, the dray_apm component processes the START_SPEED_TEST sequence and improperly evaluates the subsequent payload data. Because the application fails to adequately filter shell metacharacters or validate the syntactic structure of the input, the embedded attacker-supplied commands are concatenated or otherwise introduced into the command execution execution flow. The underlying operating system shell then executes the resulting instruction set.\nBecause the affected daemon operates with administrative privileges, any commands successfully injected via this vector execute with full root privileges. This grants the adversary complete control over the affected access point, facilitating the potential installation of persistent backdoors, modification of device configurations, pivoting to internal network segments, or disruption of wireless services. No prior authentication, user interaction, or specific cryptographic material is required to trigger the vulnerability, provided the network path to the dray_apm service is accessible."
}
CVE-2026-71914: DrayTek VigorAP Command Injection Vulnerability (CRITICAL Severity, CVSS: 9.8) - Sceawere