Junglewise Threat Intelligence

CVE-2026-71905: DrayTek VigorAP command injection in ExportSettings

CVE-2026-71905 · Severity: high · CVSS 7.2 · Published 2026-08-24

Technologies: DrayTek VigorAP 912C, DrayTek VigorAP 960C, DrayTek VigorAP 903, DrayTek VigorAP 1060C, DrayTek VigorAP 906, DrayTek VigorAP 918R. Vendors: DrayTek.

Executive brief

DrayTek VigorAP access points are wireless network devices used to provide secure enterprise connectivity. A command injection vulnerability in the settings export function allows an authenticated administrator to execute arbitrary commands with root-level privileges. An attacker with valid admin credentials could use this to gain complete control of the access point and potentially compromise the entire network.

Technical details

This is an OS command injection vulnerability (CWE-78) in the ExportSettings function of multiple VigorAP models, caused by insufficient input filtering on the backupkey, backuptype, and realtime parameters before command execution. The attack requires valid administrative credentials to authenticate to the device's web management interface. A remote attacker can inject arbitrary shell commands through these fields to achieve command execution with root privileges. Patches are available in the form of firmware updates for each affected model (versions 1.4.11 to 1.4.22 depending on the model).

Affected products

  • DrayTek VigorAP 918R before 1.4.11
  • DrayTek VigorAP 960C before 1.4.12
  • DrayTek VigorAP 1060C before 1.4.12
  • DrayTek VigorAP 906 before 1.4.13
  • DrayTek VigorAP 912C before 1.4.15
  • DrayTek VigorAP 903 before 1.4.22

Timeline

  • 2026-08-24: disclosed

References

Related threats