CVE-2026-71914

9.8

DrayTek · VigorAP

Multiple DrayTek VigorAP models are vulnerable to pre-authentication remote OS command injection via the dray_apm component.

Executive summary

A critical remote command injection vulnerability in DrayTek VigorAP devices allows unauthenticated attackers to execute arbitrary code with root privileges.

Vulnerability

This is an OS command injection flaw (CWE-78) triggered by improper validation of UDP message content in the dray_apm component. An unauthenticated remote attacker can send a crafted message to trigger execution of commands with root-level system permissions.

Business impact

The CVSS score of 9.8 reflects the high potential for total system compromise, as the vulnerability is network-accessible and requires no authentication. Successful exploitation permits full control over the affected access point, which could lead to lateral movement within the network, traffic interception, or the deployment of persistent malicious firmware.

Remediation

Immediate Action: Update all affected VigorAP models to the respective patched versions listed in the vendor security advisory.

Proactive Monitoring: Monitor network traffic for anomalous UDP packets directed at the device management ports and review system logs for unexpected process execution.

Compensating Controls: Restrict access to management interfaces to trusted IP ranges via firewall rules until firmware updates can be deployed.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the critical severity and the potential for full device takeover, administrators must prioritize the firmware update for all identified VigorAP units. Immediate patching is the only effective way to eliminate the risk of remote command execution.

More DrayTek CVEs