Executive brief
DrayTek VigorAP is a wireless access point used in enterprise networks to provide secure connectivity. The apautotest function contains a buffer overflow vulnerability that allows an authenticated administrator to trigger a denial of service condition or potentially execute arbitrary code on the device through specially crafted input. Successful exploitation requires valid administrative credentials and access to the web management interface.
Technical details
The vulnerability is a classic buffer overflow (CWE-120) in the apautotest function caused by missing length checks during memory copy operations involving the CMD6 field. A remote attacker with valid administrative credentials can supply crafted input to trigger the overflow, potentially leading to arbitrary code execution or denial of service. The attack vector is network-based but requires high privilege (authenticated admin access) to the device's web management interface. Patches are available in firmware versions 1.4.11–1.4.22 depending on the specific VigorAP model.
Affected products
- DrayTek VigorAP 918R < 1.4.11
- DrayTek VigorAP 960C < 1.4.12
- DrayTek VigorAP 1060C < 1.4.12
- DrayTek VigorAP 906 < 1.4.13
- DrayTek VigorAP 912C < 1.4.15
- DrayTek VigorAP 903 < 1.4.22
Timeline
- 2026-08-24: disclosed: Security advisory published
- 2026-08-24: patched: Patched firmware releases available (1.4.11–1.4.22 depending on model)