Junglewise Threat Intelligence

CVE-2026-71904: DrayTek VigorAP command injection in tr069TestInform

CVE-2026-71904 · Severity: high · CVSS 7.2 · Published 2026-08-24

Technologies: DrayTek VigorAP 912C, DrayTek VigorAP 960C, DrayTek VigorAP 903, DrayTek VigorAP 1060C, DrayTek VigorAP 906, DrayTek VigorAP 918R. Vendors: DrayTek.

Executive brief

DrayTek VigorAP access points are network devices used to provide wireless connectivity in business environments. A command injection vulnerability in the management interface allows authenticated administrators to execute arbitrary system commands with root privileges by submitting crafted input. An attacker with valid admin credentials could take complete control of the device, potentially compromising network traffic and connected users.

Technical details

The vulnerability is an OS command injection (CWE-78) in the tr069TestInform function caused by insufficient sanitization of the event_code parameter before it is concatenated into a system command string. The attack vector is network-based via the device's web management interface, but requires valid administrative credentials for authentication. A remote attacker can trigger the vulnerability by submitting specially crafted input containing shell metacharacters in the event_code field to execute arbitrary commands with root privileges. Patches are available in firmware updates: VigorAP 918R 1.4.11, 960C/1060C 1.4.12, 906 1.4.13, 912C 1.4.15, and 903 1.4.22.

Affected products

  • DrayTek VigorAP 918R before 1.4.11
  • DrayTek VigorAP 960C before 1.4.12
  • DrayTek VigorAP 1060C before 1.4.12
  • DrayTek VigorAP 906 before 1.4.13
  • DrayTek VigorAP 912C before 1.4.15
  • DrayTek VigorAP 903 before 1.4.22

Timeline

  • 2026-08-24: disclosed: Public advisory released by DrayTek (DSA-2026-002)
  • 2026-08-24: patched: Fixed firmware versions released for all affected models

References

Related threats