Junglewise Threat Intelligence

CVE-2026-71908: DrayTek VigorAP command injection in mesh_start_speed_test

CVE-2026-71908 · Severity: high · CVSS 7.2 · Published 2026-08-24

Technologies: DrayTek VigorAP 912C, DrayTek VigorAP 960C, DrayTek VigorAP 903, DrayTek VigorAP 1060C, DrayTek VigorAP 906, DrayTek VigorAP 918R. Vendors: DrayTek.

Executive brief

Multiple DrayTek VigorAP wireless access points contain a command injection vulnerability in a mesh network speed test function. An attacker with valid admin credentials can inject arbitrary commands that execute with root privileges, allowing complete compromise of the affected devices. This poses a serious risk to enterprise networks relying on these access points for wireless connectivity.

Technical details

A command injection vulnerability (CWE-78) exists in the mesh_start_speed_test function due to insufficient input sanitization of the meshdevice_index and meshdevice_ip parameters before OS command execution. The vulnerability is network-reachable but requires valid administrative credentials to the device's web management interface. A successful exploit allows arbitrary command execution with root privileges, leading to complete device compromise. Patches are available across all affected models with specific firmware versions (918R 1.4.11+, 960C 1.4.12+, 1060C 1.4.12+, 906 1.4.13+, 912C 1.4.15+, 903 1.4.22+).

Affected products

  • DrayTek VigorAP 918R < 1.4.11
  • DrayTek VigorAP 960C < 1.4.12
  • DrayTek VigorAP 1060C < 1.4.12
  • DrayTek VigorAP 906 < 1.4.13
  • DrayTek VigorAP 912C < 1.4.15
  • DrayTek VigorAP 903 < 1.4.22

Timeline

  • 2026-08-24: disclosed: Security advisory published by DrayTek
  • 2026-08-24: patched: Firmware updates released for all affected models

References

Related threats