Executive brief
DrayTek VigorAP wireless access points are used by organizations to provide network connectivity. A command injection vulnerability in the administrative web interface allows authenticated administrators to execute arbitrary commands with root privileges on the device. An attacker with valid admin credentials could gain complete control, disable security functions, or pivot to other network devices.
Technical details
An OS command injection vulnerability (CWE-78) exists in the upload_settings.cgi interface due to insufficient input filtering on the restorekey field before it is concatenated into a shell command. The vulnerability requires valid administrative credentials and network access to the device's web management interface. An authenticated attacker can supply crafted input containing shell metacharacters to the restorekey parameter and execute arbitrary OS commands with root privileges. Patches are available in firmware versions 1.4.11 through 1.4.22 depending on the model.
Affected products
- DrayTek VigorAP 918R < 1.4.11
- DrayTek VigorAP 960C < 1.4.12
- DrayTek VigorAP 1060C < 1.4.12
- DrayTek VigorAP 906 < 1.4.13
- DrayTek VigorAP 912C < 1.4.15
- DrayTek VigorAP 903 < 1.4.22
Timeline
- 2026-08-24: disclosed
- 2026-08-24: patched: Firmware updates released for all affected models