Junglewise Threat Intelligence

CVE-2026-71907: DrayTek VigorAP OS command injection in setcamset

CVE-2026-71907 · Severity: high · CVSS 7.2 · Published 2026-08-24

Technologies: DrayTek VigorAP 912C, DrayTek VigorAP 960C, DrayTek VigorAP 903, DrayTek VigorAP 1060C, DrayTek VigorAP 906, DrayTek VigorAP 918R. Vendors: DrayTek.

Executive brief

DrayTek VigorAP wireless access points are used to provide network connectivity in corporate and enterprise environments. An authenticated administrator with web management access can exploit a command injection vulnerability in the setcamset function to execute arbitrary commands with root privileges, potentially compromising the device and all connected network traffic.

Technical details

The vulnerability is an OS command injection flaw (CWE-78) in the setcamset function caused by insufficient input filtering on the selectSlaves parameter before command execution. Attack vector is network-based, but exploitation requires valid administrative credentials and authentication to the device's web management interface. A successful exploit allows an attacker to execute arbitrary system commands with root privileges. Patches are available in fixed firmware versions: VigorAP 918R 1.4.11, VigorAP 960C/1060C 1.4.12, VigorAP 906 1.4.13, VigorAP 912C 1.4.15, and VigorAP 903 1.4.22.

Affected products

  • DrayTek VigorAP 918R < 1.4.11
  • DrayTek VigorAP 960C < 1.4.12
  • DrayTek VigorAP 1060C < 1.4.12
  • DrayTek VigorAP 906 < 1.4.13
  • DrayTek VigorAP 912C < 1.4.15
  • DrayTek VigorAP 903 < 1.4.22

Timeline

  • 2026-08-24: disclosed
  • 2026-08-24: patched: Fixed firmware released for all affected models

References

Related threats