CVE-2026-71923
DrayTek VigorSwitch Multiple Models OS Command Injection via auth_set
CVSS Score
7.2
EPSS Score
0.0%
EPSS Percentile
0th
Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the auth_set function. The vulnerability is caused by insufficient filtering of the username and password fields before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administrative credentials for the device's web management interface.
| CWE | CWE-78 |
| Vendor | draytek corporation |
| Product | vigorswitch g2540xs |
| Published | Aug 24, 2026 |
Stay Ahead of the Next One
Get instant alerts for draytek corporation vigorswitch g2540xs
Be the first to know when new high vulnerabilities affecting draytek corporation vigorswitch g2540xs are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected Versions
DrayTek Corporation / VigorSwitch G2540xs
0 < 3.9.10
DrayTek Corporation / VigorSwitch P2540xs
0 < 3.9.10
DrayTek Corporation / VigorSwitch FX2120
0 < 3.9.10
DrayTek Corporation / VigorSwitch G2282x
0 < 2.10.6
DrayTek Corporation / VigorSwitch P2282x
0 < 2.10.6
DrayTek Corporation / VigorSwitch Q2300x
0 < 2.10.7
DrayTek Corporation / VigorSwitch PQ2300xb
0 < 2.10.7
DrayTek Corporation / VigorSwitch G2542x
0 < 3.10.6
DrayTek Corporation / VigorSwitch P2542x
0 < 3.10.6
DrayTek Corporation / VigorSwitch P2542xh
0 < 3.10.6
DrayTek Corporation / VigorSwitch PX2060
0 < 2.9.10
DrayTek Corporation / VigorSwitch G1280
0 < 2.9.10
DrayTek Corporation / VigorSwitch P1280
0 < 2.9.10
DrayTek Corporation / VigorSwitch P1281x
0 < 2.9.10
DrayTek Corporation / VigorSwitch G1282
0 < 2.9.10
DrayTek Corporation / VigorSwitch P1282
0 < 2.9.10
DrayTek Corporation / VigorSwitch G2121
0 < 2.9.10
DrayTek Corporation / VigorSwitch P2121
0 < 2.9.10
DrayTek Corporation / VigorSwitch PQ2121x
0 < 2.9.10
DrayTek Corporation / VigorSwitch Q2121x
0 < 2.9.10
DrayTek Corporation / VigorSwitch G2280x
0 < 2.9.10
DrayTek Corporation / VigorSwitch P2280x
0 < 2.9.10
DrayTek Corporation / VigorSwitch Q2200x
0 < 2.9.10
DrayTek Corporation / VigorSwitch PQ2200xb
0 < 2.9.10
DrayTek Corporation / VigorSwitch G2100
0 < 2.9.10
DrayTek Corporation / VigorSwitch P2100
0 < 2.9.10
DrayTek Corporation / VigorSwitch G2540x
0 < 2.9.10
DrayTek Corporation / VigorSwitch P2540x
0 < 2.9.10
References
Credits
Jincheng Wang (@winmt) Le Yu (Nanjing University of Posts and Telecommunications) Xiapu Luo (The Hong Kong Polytechnic University)