Junglewise Threat Intelligence

CVE-2026-71924: DrayTek VigorSwitch command injection in getVid function

CVE-2026-71924 · Severity: high · CVSS 7.2 · Published 2026-08-24

Technologies: DrayTek VigorSwitch PX2060, DrayTek VigorSwitch G2100, DrayTek VigorSwitch G2540xs, DrayTek VigorSwitch G1280, DrayTek VigorSwitch PQ2200xb, DrayTek VigorSwitch P2540xs, DrayTek VigorSwitch FX2120, DrayTek VigorSwitch P1280, DrayTek VigorSwitch P2121, DrayTek VigorSwitch P1281x, DrayTek VigorSwitch G2542x, DrayTek VigorSwitch Q2121x, DrayTek VigorSwitch PQ2300xb, DrayTek VigorSwitch G2540x, DrayTek VigorSwitch P2100, DrayTek VigorSwitch P2280x, DrayTek VigorSwitch G2121, DrayTek VigorSwitch Q2300x, DrayTek VigorSwitch P2542x, DrayTek VigorSwitch G2280x, DrayTek VigorSwitch PQ2121x, DrayTek VigorSwitch P2542xh, DrayTek VigorSwitch G1282, DrayTek VigorSwitch Q2200x, DrayTek VigorSwitch P2282x, DrayTek VigorSwitch P1282, DrayTek VigorSwitch G2282x, DrayTek VigorSwitch P2540x. Vendors: DrayTek.

Executive brief

DrayTek VigorSwitch is a managed network switch used to control and monitor data traffic in enterprise networks. A command injection vulnerability in the device's administrative interface allows authenticated attackers to execute arbitrary system commands with root-level privileges by crafting malicious input in the username and password fields. Compromise of a VigorSwitch could lead to complete network takeover, data interception, and disruption of critical business operations.

Technical details

The vulnerability is a command injection flaw (CWE-78) in the getVid function within the mainfunction.cgi component of DrayTek VigorSwitch firmware. The root cause is insufficient input filtering and sanitization of the username and password fields before they are passed to OS command execution routines. Attack vector is network-based via the web management interface; exploitation requires valid administrative credentials and network access to the management interface. An attacker with admin credentials can inject shell metacharacters into these fields to execute arbitrary OS commands as root. DrayTek has released patched firmware versions (varying by model, e.g., 3.9.10, 2.10.6, 3.10.6, 2.9.10) that address this vulnerability.

Affected products

  • DrayTek VigorSwitch G2540xs before 3.9.10
  • DrayTek VigorSwitch P2540xs before 3.9.10
  • DrayTek VigorSwitch FX2120 before 3.9.10
  • DrayTek VigorSwitch G2282x before 2.10.6
  • DrayTek VigorSwitch P2282x before 2.10.6
  • DrayTek VigorSwitch Q2300x before 2.10.7
  • DrayTek VigorSwitch PQ2300xb before 2.10.7
  • DrayTek VigorSwitch G2542x before 3.10.6
  • DrayTek VigorSwitch P2542x before 3.10.6
  • DrayTek VigorSwitch P2542xh before 3.10.6
  • DrayTek VigorSwitch PX2060 before 2.9.10
  • DrayTek VigorSwitch G1280 before 2.9.10
  • DrayTek VigorSwitch P1280 before 2.9.10
  • DrayTek VigorSwitch P1281x before 2.9.10
  • DrayTek VigorSwitch G1282 before 2.9.10
  • DrayTek VigorSwitch P1282 before 2.9.10
  • DrayTek VigorSwitch G2121 before 2.9.10
  • DrayTek VigorSwitch P2121 before 2.9.10
  • DrayTek VigorSwitch PQ2121x before 2.9.10
  • DrayTek VigorSwitch Q2121x before 2.9.10
  • DrayTek VigorSwitch G2280x before 2.9.10
  • DrayTek VigorSwitch P2280x before 2.9.10
  • DrayTek VigorSwitch Q2200x before 2.9.10
  • DrayTek VigorSwitch PQ2200xb before 2.9.10
  • DrayTek VigorSwitch G2100 before 2.9.10
  • DrayTek VigorSwitch P2100 before 2.9.10
  • DrayTek VigorSwitch G2540x before 2.9.10
  • DrayTek VigorSwitch P2540x before 2.9.10

Timeline

  • 2026-08-24: disclosed
  • 2026-08-24: patched: Firmware updates released for affected models

References

Related threats