Junglewise Threat Intelligence

CVE-2026-71914: DrayTek VigorAP command injection in dray_apm

CVE-2026-71914 · Severity: critical · CVSS 9.8 · Published 2026-08-24

Technologies: DrayTek VigorAP 912C, DrayTek VigorAP 960C, DrayTek VigorAP 903, DrayTek VigorAP 1060C, DrayTek VigorAP 906, DrayTek VigorAP 918R. Vendors: DrayTek.

Executive brief

DrayTek VigorAP is a wireless access point used in enterprise networks. This vulnerability allows an unauthenticated remote attacker to execute arbitrary commands with root privileges on affected appliances by sending a specially crafted network message, potentially leading to complete compromise of network infrastructure and sensitive data exposure.

Technical details

The vulnerability is an OS command injection flaw (CWE-78) in the dray_apm component of DrayTek VigorAP access points. The vulnerable code fails to properly validate UDP message content following a START_SPEED_TEST message, allowing special command characters to pass through unfiltered before execution. An unauthenticated remote attacker can send a crafted UDP packet to trigger the injection, resulting in arbitrary command execution with root privileges on the device. No authentication or user interaction is required. Firmware updates are available for all affected models.

Affected products

  • DrayTek VigorAP 918R before 1.4.11
  • DrayTek VigorAP 960C before 1.4.12
  • DrayTek VigorAP 1060C before 1.4.12
  • DrayTek VigorAP 906 before 1.4.13
  • DrayTek VigorAP 912C before 1.4.15
  • DrayTek VigorAP 903 before 1.4.22

Timeline

  • 2026-08-24: disclosed

References

Related threats