Junglewise Threat Intelligence

CVE-2026-71919: DrayTek VigorSwitch command injection in sysreboot

CVE-2026-71919 · Severity: high · CVSS 7.2 · Published 2026-08-24

Technologies: DrayTek VigorSwitch PX2060, DrayTek VigorSwitch G2100, DrayTek VigorSwitch G2540xs, DrayTek VigorSwitch G1280, DrayTek VigorSwitch PQ2200xb, DrayTek VigorSwitch P2540xs, DrayTek VigorSwitch FX2120, DrayTek VigorSwitch P1280, DrayTek VigorSwitch P2121, DrayTek VigorSwitch P1281x, DrayTek VigorSwitch G2542x, DrayTek VigorSwitch Q2121x, DrayTek VigorSwitch PQ2300xb, DrayTek VigorSwitch G2540x, DrayTek VigorSwitch P2100, DrayTek VigorSwitch P2280x, DrayTek VigorSwitch G2121, DrayTek VigorSwitch Q2300x, DrayTek VigorSwitch P2542x, DrayTek VigorSwitch G2280x, DrayTek VigorSwitch PQ2121x, DrayTek VigorSwitch P2542xh, DrayTek VigorSwitch G1282, DrayTek VigorSwitch Q2200x, DrayTek VigorSwitch P2282x, DrayTek VigorSwitch P1282, DrayTek VigorSwitch G2282x, DrayTek VigorSwitch P2540x. Vendors: DrayTek.

Executive brief

DrayTek VigorSwitch network switches are used to manage enterprise network traffic. The vulnerability allows authenticated administrators to inject arbitrary shell commands through the sysreboot function, gaining root-level control over the device. This could enable an attacker with valid admin credentials to completely compromise the switch, disrupt network operations, or pivot to other network segments.

Technical details

The vulnerability is a command injection flaw (CWE-78) in the mainfunction.cgi component's sysreboot function, caused by insufficient sanitization of the config, act, pathN, and valueN parameters before passing them to OS command execution. The attack is network-accessible via the web management interface and requires valid administrative credentials for authentication. A successful exploit allows arbitrary command execution with root privileges on the affected appliance. Patches have been released for all affected models with updated firmware versions ranging from 2.9.10 to 3.10.6.

Affected products

  • DrayTek VigorSwitch G2540xs < 3.9.10
  • DrayTek VigorSwitch P2540xs < 3.9.10
  • DrayTek VigorSwitch FX2120 < 3.9.10
  • DrayTek VigorSwitch G2282x < 2.10.6
  • DrayTek VigorSwitch P2282x < 2.10.6
  • DrayTek VigorSwitch Q2300x < 2.10.7
  • DrayTek VigorSwitch PQ2300xb < 2.10.7
  • DrayTek VigorSwitch G2542x < 3.10.6
  • DrayTek VigorSwitch P2542x < 3.10.6
  • DrayTek VigorSwitch P2542xh < 3.10.6
  • DrayTek VigorSwitch PX2060 < 2.9.10
  • DrayTek VigorSwitch G1280 < 2.9.10
  • DrayTek VigorSwitch P1280 < 2.9.10
  • DrayTek VigorSwitch P1281x < 2.9.10
  • DrayTek VigorSwitch G1282 < 2.9.10
  • DrayTek VigorSwitch P1282 < 2.9.10
  • DrayTek VigorSwitch G2121 < 2.9.10
  • DrayTek VigorSwitch P2121 < 2.9.10
  • DrayTek VigorSwitch PQ2121x < 2.9.10
  • DrayTek VigorSwitch Q2121x < 2.9.10
  • DrayTek VigorSwitch G2280x < 2.9.10
  • DrayTek VigorSwitch P2280x < 2.9.10
  • DrayTek VigorSwitch Q2200x < 2.9.10
  • DrayTek VigorSwitch PQ2200xb < 2.9.10
  • DrayTek VigorSwitch G2100 < 2.9.10
  • DrayTek VigorSwitch P2100 < 2.9.10
  • DrayTek VigorSwitch G2540x < 2.9.10
  • DrayTek VigorSwitch P2540x < 2.9.10

Timeline

  • 2026-08-24: disclosed
  • 2026-08-24: patched: Firmware updates released for all affected models

References

Related threats