Sceawere

Vulnerability Detail

CVE-2026-71928UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

DrayTek VigorSwitch Command Injection Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.2
Creation Date
4h ago
Vendor
DrayTek Corporation
Product
VigorSwitch G2540xs
Attack Type
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the fdftDevice function. The vulnerability is caused by insufficient filtering of the username and password fields before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administrative credentials for the device's web management interface.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.2",
  "pubDate": "2026-08-24T18:17:08.303Z",
  "pubdate": "2026-08-24T18:17:08.303Z",
  "executiveSummary": "Multiple DrayTek VigorSwitch models suffer from a critical command injection vulnerability located within the fdftDevice function of the device's web management interface. This security flaw stems from the inadequate sanitization and filtering of user-supplied input submitted via the username and password authentication fields prior to being processed by underlying system command execution routines.\nSuccessfully exploiting this vulnerability enables an authenticated remote attacker to bypass intended input boundaries and execute arbitrary system commands directly on the underlying operating system. Because the affected web management services typically operate with elevated system privileges, successful exploitation results in complete compromise of the targeted network device with root privileges.\nAlthough the attack surface is exposed remotely via the web management interface, exploitation mandates the prerequisite acquisition and use of valid administrative credentials to interact with the vulnerable authentication mechanism. The resulting impact compromises the confidentiality, integrity, and availability of the affected switch and potentially provides a malicious actor with a persistent foothold within the local network infrastructure. Organizations utilizing vulnerable DrayTek VigorSwitch models face significant risk exposure if administrative interfaces are accessible from untrusted networks or compromised internal zones.",
  "technicalDetails": "The vulnerability resides in the fdftDevice function handling administrative authentication processes within multiple DrayTek VigorSwitch models. The root cause of the security flaw is improper input validation and insufficient sanitization of parameters accepted through the username and password fields exposed by the web management interface.\nWhen a user attempts to authenticate, the application improperly handles specific meta-characters or payload strings within the authentication parameters. Instead of securely processing these values or utilizing safe API abstractions for system interactions, the vulnerable component passes the unsanitized input directly into command execution routines. This flaw allows malicious input to alter the syntax of the executed system command, facilitating operating system command injection.\nThe attack flow proceeds as follows: First, a remote attacker establishes network connectivity to the web management interface of the target DrayTek VigorSwitch. Second, the attacker supplies valid administrative credentials alongside a specially crafted payload injected into the username or password parameters. Third, the HTTP request is processed by the web server, invoking the vulnerable fdftDevice function. Fourth, the application fails to filter the malicious input and appends the attacker's payload directly to a system command execution string. Finally, the underlying operating system executes the resulting concatenated command.\nExploitation requires network access to the device management service and valid administrative credentials, meaning the threat actor must either compromise administrative accounts beforehand or leverage default or weak credentials if present. The payload executes with root privileges, granting the attacker unrestricted control over the affected hardware. Post-exploitation activities can include modifying device configurations, intercepting network traffic, establishing persistent backdoors, or pivoting deeper into the internal network topology."
}
CVE-2026-71928: DrayTek VigorSwitch Command Injection Vulnerability (HIGH Severity, CVSS: 7.2) - Sceawere