Sceawere

Vulnerability Detail

CVE-2026-71917UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

DrayTek VigorSwitch Pingtrace Command Injection

Vulnerability Metadata

Severity
High
Score / CVSS
7.2
Creation Date
4h ago
Vendor
DrayTek Corporation
Product
VigorSwitch G2540xs
Attack Type
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the pingtrace function. The vulnerability is caused by insufficient validation of the host field before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administrative credentials for the device's web management interface.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.2",
  "pubDate": "2026-08-24T18:17:06.153Z",
  "pubdate": "2026-08-24T18:17:06.153Z",
  "executiveSummary": "A command injection vulnerability exists within the pingtrace function across multiple DrayTek VigorSwitch models. The security flaw stems from the insufficient validation and sanitization of user-supplied input within the host parameter before it is passed to the underlying operating system for execution.\nSuccessfully exploiting this vulnerability allows a remote authenticated attacker to execute arbitrary system commands with elevated root privileges on the targeted network device. The primary impact of this vulnerability includes total compromise of the affected switch, potential lateral movement within the local network, disruption of network services, and unauthorized access to administrative controls.\nExploitation of this vulnerability requires valid administrative credentials to access the device's web management interface, meaning the attacker must either possess legitimate credentials or leverage a separate authentication bypass or social engineering vector. The risk implications are severe given that compromised network infrastructure devices can be utilized to intercept traffic, modify routing configurations, and facilitate persistent internal reconnaissance or pivoting against enterprise networks.",
  "technicalDetails": "The vulnerability resides within the pingtrace function implemented in the web management interface of multiple DrayTek VigorSwitch models. The root cause of the security flaw is improper input handling and the lack of robust sanitization or parameterization of the host field prior to command execution. When an administrative user invokes the pingtrace diagnostic utility via the web interface, the input provided in the host parameter is concatenated directly into a system command string and executed by the underlying shell with root privileges.\nThe attack flow proceeds as follows: First, the remote attacker obtains valid administrative credentials to authenticate against the web management interface of the target DrayTek VigorSwitch. Second, the attacker navigates to the diagnostic utility corresponding to the pingtrace function. Third, the attacker intercepts or crafts an HTTP request containing malicious, shell-metacharacter-infused payloads within the host field. Because the vulnerable component fails to adequately filter inputs such as semicolons, pipe symbols, or backticks, the operating system executes the attacker-supplied commands concurrently or sequentially following the intended diagnostic utility execution.\nThe vulnerable component is the web management interface handling the pingtrace diagnostic feature. The network exposure is remote, as the management interface is typically accessible over the local area network or potentially exposed to the WAN if misconfigured. Authentication requirements mandate valid administrative credentials, and privilege requirements are absolute, granting the executed payload root privileges upon successful exploitation. Post-exploitation impact includes arbitrary command execution, persistence installation, firmware manipulation, traffic interception, and complete administrative takeover of the affected DrayTek VigorSwitch."
}
CVE-2026-71917: DrayTek VigorSwitch Pingtrace Command Injection (HIGH Severity, CVSS: 7.2) - Sceawere