CVE-2026-71922
7.5DrayTek · VigorSwitch
Multiple DrayTek VigorSwitch models are susceptible to a pre-authentication null pointer dereference vulnerability, potentially causing a denial of service.
Executive summary
A high-severity pre-authentication denial of service vulnerability in various DrayTek VigorSwitch models allows unauthenticated attackers to crash the device remotely.
Vulnerability
The device firmware contains a NULL pointer dereference flaw (CWE-476) in the setget CGI interface, which can be triggered without authentication to crash the system's service.
Business impact
An attacker can disrupt network operations by causing a denial of service on critical switching infrastructure. With a CVSS score of 7.5, this vulnerability represents a significant operational risk, as network outages can lead to substantial downtime for connected services and business processes.
Remediation
Immediate Action: Apply the vendor-provided firmware updates (3.9.10, 2.10.6, or 2.10.7, depending on the model) as specified in the official DrayTek security advisory.
Proactive Monitoring: Monitor network device logs for unexpected reboots or service interruptions that may indicate exploitation attempts.
Compensating Controls: Restrict access to the switch management interface to trusted administrative IP addresses using Access Control Lists (ACLs).
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Maintaining network availability is critical for business continuity. Administrators should verify the specific VigorSwitch model in use and apply the corresponding firmware patch immediately to mitigate the risk of remote service disruption.