Executive brief
DrayTek VigorAP is a wireless access point used to provide network connectivity in business and enterprise environments. A command injection vulnerability in the device's web management interface allows authenticated administrators with valid credentials to execute arbitrary commands with root-level privileges, potentially compromising the access point and the network it serves.
Technical details
The vulnerability is an OS command injection flaw (CWE-78) in the apautotest function within DrayTek VigorAP firmware. The vulnerable code fails to properly validate or sanitize the CMD0, CMD3, and CMD6 input fields before passing them to operating system command execution routines. An attacker who possesses valid administrative credentials and gains authenticated access to the device's web management interface can supply specially crafted input containing shell metacharacters or command sequences to achieve arbitrary command execution with root privileges. Patches are available in the form of firmware updates for all affected models (VigorAP 918R 1.4.11+, 960C/1060C 1.4.12+, 906 1.4.13+, 912C 1.4.15+, and 903 1.4.22+).
Affected products
- DrayTek VigorAP 918R before 1.4.11
- DrayTek VigorAP 960C before 1.4.12
- DrayTek VigorAP 1060C before 1.4.12
- DrayTek VigorAP 906 before 1.4.13
- DrayTek VigorAP 912C before 1.4.15
- DrayTek VigorAP 903 before 1.4.22
Timeline
- 2026-08-24: disclosed
- 2026-08-24: patched: Firmware updates released for all affected models