Junglewise Threat Intelligence

CVE-2026-71906: DrayTek VigorAP OS command injection in setLan

CVE-2026-71906 · Severity: high · CVSS 7.2 · Published 2026-08-24

Technologies: DrayTek VigorAP 912C, DrayTek VigorAP 960C, DrayTek VigorAP 903, DrayTek VigorAP 1060C, DrayTek VigorAP 906, DrayTek VigorAP 918R. Vendors: DrayTek.

Executive brief

DrayTek VigorAP access points are network devices that provide wireless connectivity in corporate and enterprise environments. A command injection vulnerability in the network configuration function allows authenticated administrators to execute arbitrary system commands with root privileges on the device. An attacker with valid admin credentials could compromise the access point, potentially leading to network outages, data interception, or lateral movement within the network.

Technical details

The vulnerability is an OS command injection flaw (CWE-78) in the setLan function, caused by insufficient validation of the lanIp and lanNetmask input fields before they are used in system command execution. The attack vector is network-based; however, exploitation requires valid administrative credentials and authentication to the device's web management interface, making this a high-privilege attack requiring prior account compromise or insider access. A successful exploit enables an attacker to execute arbitrary commands with root privileges on the VigorAP device. DrayTek has released patched firmware versions for all affected models (VigorAP 903, 906, 912C, 918R, 960C, and 1060C), and users should upgrade immediately to mitigate this risk.

Affected products

  • DrayTek VigorAP 918R < 1.4.11
  • DrayTek VigorAP 960C < 1.4.12
  • DrayTek VigorAP 1060C < 1.4.12
  • DrayTek VigorAP 906 < 1.4.13
  • DrayTek VigorAP 912C < 1.4.15
  • DrayTek VigorAP 903 < 1.4.22

Timeline

  • 2026-08-24: disclosed
  • 2026-08-24: patched

References

Related threats