Sceawere

Vulnerability Detail

CVE-2026-71933UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

DrayTek VigorSwitch Syslog Unauthorized Operation Vulnerability

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.1
Creation Date
4h ago
Vendor
DrayTek Corporation
Product
VigorSwitch G2540xs
Attack Type
Missing Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Multiple DrayTek VigorSwitch models contain unauthorized operation vulnerabilities in multiple syslog functions. The vulnerability is caused by missing authorization checks. A remote attacker can trigger these vulnerabilities via crafted requests to modify configuration, restart services, save startup configuration, or clear logs.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.1",
  "pubDate": "2026-08-24T18:17:18.090Z",
  "pubdate": "2026-08-24T18:17:18.090Z",
  "executiveSummary": "Multiple DrayTek VigorSwitch models contain unauthorized operation vulnerabilities within multiple syslog functions, presenting a severe risk to network infrastructure integrity and availability.\nThe core vulnerability type is characterized by a complete absence of proper authorization checks, allowing remote unauthenticated threat actors to execute privileged administrative operations.\nThe potential impact includes unauthorized system configuration modifications, arbitrary service restarts, malicious alteration or persistence of startup configurations, and the clearing of essential audit logs to cover attacker footprints.\nAffected systems are restricted to multiple DrayTek VigorSwitch models utilizing vulnerable firmware implementations of the syslog subsystem.\nRisk implications are substantial, as successful exploitation enables full device compromise, potential man-in-the-middle positioning, lateral network pivoting, and disruption of critical logging and monitoring capabilities.\nAttacker capabilities require network access to the switch management interface or affected syslog services, enabling the submission of specially crafted network requests.\nNo specific version numbers, file paths, or specialized privileges are mandated by the vulnerability mechanics beyond the ability to transmit crafted protocol payloads directly to the vulnerable component.\nRemediation requires the application of vendor-supplied firmware patches or the immediate implementation of strict network segmentation and access control lists to restrict management plane exposure.",
  "technicalDetails": "The root cause of the vulnerability stems from missing authorization checks within multiple syslog functions implemented across affected DrayTek VigorSwitch models.\nThe vulnerable component resides in the device firmware handling syslog-related routines, which fails to validate whether the entity issuing a request possesses the administrative privileges required to invoke sensitive routines.\nAuthentication and privilege requirements are entirely bypassed due to the flawed implementation of access control logic within the target functions, permitting unauthenticated remote actors to issue administrative commands.\nNetwork exposure is inherent to the management and administrative planes of the affected switches, where remote attackers can interact with the vulnerable service over the network via crafted requests.\nThe attack flow begins when a remote attacker formulates a specially crafted request targeted at vulnerable syslog endpoints or associated administrative functions on the DrayTek VigorSwitch.\nBecause the application layer code completely omits authorization verification steps prior to executing core logic, the switch processes the incoming payload as a legitimate administrative command.\nPayload behavior manifests through the execution of unauthorized operations, which include modifying system configurations, initiating a restart of core system services, forcing the saving of a malicious or modified startup configuration, and clearing security or system logs.\nPost-exploitation impact includes persistent unauthorized control over the network switch, denial of service via service restarts, evasion of detection through log clearance, and degradation of overall network visibility and operational security.\nThe absence of input validation coupled with missing authorization primitives allows for seamless execution of state-changing administrative actions without requiring valid session tokens, credentials, or prior authentication handshakes."
}
CVE-2026-71933: DrayTek VigorSwitch Syslog Unauthorized Operation Vulnerability (CRITICAL Severity, CVSS: 9.1) - Sceawere