Junglewise Threat Intelligence

CVE-2026-71909: DrayTek VigorAP command injection in InquierTime function

CVE-2026-71909 · Severity: high · CVSS 7.2 · Published 2026-08-24

Technologies: DrayTek VigorAP 912C, DrayTek VigorAP 960C, DrayTek VigorAP 903, DrayTek VigorAP 1060C, DrayTek VigorAP 906, DrayTek VigorAP 918R. Vendors: DrayTek.

Executive brief

DrayTek VigorAP is a wireless access point used in corporate networks. Multiple models contain a command injection flaw in the time configuration function that allows an authenticated attacker to execute arbitrary commands with root privileges on the device. An attacker with valid admin credentials could compromise the access point and potentially gain control over network traffic passing through it.

Technical details

A command injection vulnerability (CWE-78) exists in the InquierTime function across multiple VigorAP models due to insufficient sanitization of the time field parameter before shell command execution. The attack vector is network-based and requires valid administrative credentials to access the web management interface; no user interaction is needed once authenticated. A successful exploit allows an attacker to execute arbitrary OS commands with root-level privileges. Patches are available in the following fixed firmware versions: VigorAP 918R 1.4.11, VigorAP 960C/1060C 1.4.12, VigorAP 906 1.4.13, VigorAP 912C 1.4.15, and VigorAP 903 1.4.22.

Affected products

  • DrayTek VigorAP 918R before 1.4.11
  • DrayTek VigorAP 960C before 1.4.12
  • DrayTek VigorAP 1060C before 1.4.12
  • DrayTek VigorAP 906 before 1.4.13
  • DrayTek VigorAP 912C before 1.4.15
  • DrayTek VigorAP 903 before 1.4.22

Timeline

  • 2026-08-24: disclosed: DrayTek security advisory DSA-2026-002 published
  • 2026-08-24: patched: Firmware patches released for all affected models

References

Related threats