CVE-2026-71921

9.8

DrayTek · VigorSwitch

Multiple DrayTek VigorSwitch models are susceptible to pre-authentication OS command injection via the setget.cgi interface.

Executive summary

A critical command injection vulnerability in DrayTek VigorSwitch models enables unauthenticated attackers to execute arbitrary system commands with root privileges.

Vulnerability

The vulnerability (CWE-78) exists in the setget.cgi interface, where the pass parameter is insufficiently filtered. An unauthenticated attacker can supply crafted input to the interface to achieve remote code execution at the root level.

Business impact

With a CVSS score of 9.8, this vulnerability represents an severe risk to network infrastructure. Compromise of a network switch allows an attacker to manipulate traffic flows, mirror packets for espionage, or gain a foothold to attack other connected internal resources.

Remediation

Immediate Action: Apply the vendor-provided firmware updates to the affected VigorSwitch models immediately.

Proactive Monitoring: Review switch management logs for suspicious HTTP requests targeting the setget.cgi interface and monitor for unauthorized configuration changes.

Compensating Controls: Implement strict network segmentation and ensure that switch management interfaces are not accessible from untrusted or public-facing networks.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Administrators should treat this vulnerability with the highest urgency. Because the flaw allows for root-level access via the management interface, applying the latest firmware patch is necessary to maintain the integrity of the network environment.

More DrayTek CVEs