Executive brief
Multiple DrayTek VigorAP wireless access points contain a command injection vulnerability in a mesh network speed test function. An attacker with valid admin credentials can inject arbitrary commands that execute with root privileges, allowing complete compromise of the affected devices. This poses a serious risk to enterprise networks relying on these access points for wireless connectivity.
Technical details
A command injection vulnerability (CWE-78) exists in the mesh_start_speed_test function due to insufficient input sanitization of the meshdevice_index and meshdevice_ip parameters before OS command execution. The vulnerability is network-reachable but requires valid administrative credentials to the device's web management interface. A successful exploit allows arbitrary command execution with root privileges, leading to complete device compromise. Patches are available across all affected models with specific firmware versions (918R 1.4.11+, 960C 1.4.12+, 1060C 1.4.12+, 906 1.4.13+, 912C 1.4.15+, 903 1.4.22+).
Affected products
- DrayTek VigorAP 918R < 1.4.11
- DrayTek VigorAP 960C < 1.4.12
- DrayTek VigorAP 1060C < 1.4.12
- DrayTek VigorAP 906 < 1.4.13
- DrayTek VigorAP 912C < 1.4.15
- DrayTek VigorAP 903 < 1.4.22
Timeline
- 2026-08-24: disclosed: Security advisory published by DrayTek
- 2026-08-24: patched: Firmware updates released for all affected models