CVE-2026-71922

7.5

DrayTek · VigorSwitch

Multiple DrayTek VigorSwitch models are susceptible to a pre-authentication null pointer dereference vulnerability, potentially causing a denial of service.

Executive summary

A high-severity pre-authentication denial of service vulnerability in various DrayTek VigorSwitch models allows unauthenticated attackers to crash the device remotely.

Vulnerability

The device firmware contains a NULL pointer dereference flaw (CWE-476) in the setget CGI interface, which can be triggered without authentication to crash the system's service.

Business impact

An attacker can disrupt network operations by causing a denial of service on critical switching infrastructure. With a CVSS score of 7.5, this vulnerability represents a significant operational risk, as network outages can lead to substantial downtime for connected services and business processes.

Remediation

Immediate Action: Apply the vendor-provided firmware updates (3.9.10, 2.10.6, or 2.10.7, depending on the model) as specified in the official DrayTek security advisory.

Proactive Monitoring: Monitor network device logs for unexpected reboots or service interruptions that may indicate exploitation attempts.

Compensating Controls: Restrict access to the switch management interface to trusted administrative IP addresses using Access Control Lists (ACLs).

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Maintaining network availability is critical for business continuity. Administrators should verify the specific VigorSwitch model in use and apply the corresponding firmware patch immediately to mitigate the risk of remote service disruption.

More DrayTek CVEs