Executive brief
DrayTek VigorAP wireless access points contain a buffer overflow vulnerability in network configuration handling. An attacker with administrative access to the web management interface can send malicious input to trigger the flaw, potentially causing the device to crash or execute arbitrary code. This affects multiple VigorAP models used to provide wireless connectivity in enterprise environments.
Technical details
The vulnerability is a classic buffer overflow (CWE-120) in the setLan function caused by missing length validation during memory copy operations on the lanVlanId0, lanIp, and lanNetmask fields. The flaw can be triggered remotely via crafted HTTP requests to the device's web management interface, but requires valid administrative credentials for authentication. Successful exploitation could result in denial of service or remote code execution with device privileges. Firmware patches are available for all affected models: VigorAP 918R (1.4.11+), 960C (1.4.12+), 1060C (1.4.12+), 906 (1.4.13+), 912C (1.4.15+), and 903 (1.4.22+).
Affected products
- DrayTek VigorAP 918R before 1.4.11
- DrayTek VigorAP 960C before 1.4.12
- DrayTek VigorAP 1060C before 1.4.12
- DrayTek VigorAP 906 before 1.4.13
- DrayTek VigorAP 912C before 1.4.15
- DrayTek VigorAP 903 before 1.4.22
Timeline
- 2026-08-24: disclosed: Vulnerability disclosed and firmware patches released