Junglewise Threat Intelligence

CVE-2026-71910: DrayTek VigorAP OS command injection in apautotest

CVE-2026-71910 · Severity: high · CVSS 7.2 · Published 2026-08-24

Technologies: DrayTek VigorAP 912C, DrayTek VigorAP 1060C, DrayTek VigorAP 906, DrayTek VigorAP 903, DrayTek VigorAP 918R, DrayTek VigorAP 960C. Vendors: DrayTek.

Executive brief

DrayTek VigorAP is a wireless access point used to provide network connectivity in business and enterprise environments. A command injection vulnerability in the device's web management interface allows authenticated administrators with valid credentials to execute arbitrary commands with root-level privileges, potentially compromising the access point and the network it serves.

Technical details

The vulnerability is an OS command injection flaw (CWE-78) in the apautotest function within DrayTek VigorAP firmware. The vulnerable code fails to properly validate or sanitize the CMD0, CMD3, and CMD6 input fields before passing them to operating system command execution routines. An attacker who possesses valid administrative credentials and gains authenticated access to the device's web management interface can supply specially crafted input containing shell metacharacters or command sequences to achieve arbitrary command execution with root privileges. Patches are available in the form of firmware updates for all affected models (VigorAP 918R 1.4.11+, 960C/1060C 1.4.12+, 906 1.4.13+, 912C 1.4.15+, and 903 1.4.22+).

Affected products

  • DrayTek VigorAP 918R before 1.4.11
  • DrayTek VigorAP 960C before 1.4.12
  • DrayTek VigorAP 1060C before 1.4.12
  • DrayTek VigorAP 906 before 1.4.13
  • DrayTek VigorAP 912C before 1.4.15
  • DrayTek VigorAP 903 before 1.4.22

Timeline

  • 2026-08-24: disclosed
  • 2026-08-24: patched: Firmware updates released for all affected models

References

Related threats