Executive brief
DrayTek VigorSwitch is a managed network switch used to segment and control corporate network traffic. A command injection vulnerability in the device's web management interface allows authenticated administrators to execute arbitrary system commands with root-level privileges by submitting malicious input in username and password fields, potentially enabling full system compromise and lateral movement within the network.
Technical details
The vulnerability is a classic OS command injection (CWE-78) in the rebDevice function within the mainfunction.cgi component of VigorSwitch firmware. The root cause is insufficient input validation and filtering of the username and password fields before they are passed to a command execution context. Attack vector is network-based via the device's web management interface; however, exploitation requires valid administrative credentials—reducing the attack surface to authenticated insiders or attackers with compromised admin accounts. A successful exploit allows arbitrary command execution with root privileges on the affected appliance. Patches are available in fixed firmware versions released August 2026 for all affected VigorSwitch models.
Affected products
- DrayTek VigorSwitch G2540xs < 3.9.10
- DrayTek VigorSwitch P2540xs < 3.9.10
- DrayTek VigorSwitch FX2120 < 3.9.10
- DrayTek VigorSwitch G2282x < 2.10.6
- DrayTek VigorSwitch P2282x < 2.10.6
- DrayTek VigorSwitch Q2300x < 2.10.7
- DrayTek VigorSwitch PQ2300xb < 2.10.7
- DrayTek VigorSwitch G2542x < 3.10.6
- DrayTek VigorSwitch P2542x < 3.10.6
- DrayTek VigorSwitch P2542xh < 3.10.6
- DrayTek VigorSwitch PX2060 < 2.9.10
- DrayTek VigorSwitch G1280 < 2.9.10
- DrayTek VigorSwitch P1280 < 2.9.10
- DrayTek VigorSwitch P1281x < 2.9.10
- DrayTek VigorSwitch G1282 < 2.9.10
- DrayTek VigorSwitch P1282 < 2.9.10
- DrayTek VigorSwitch G2121 < 2.9.10
- DrayTek VigorSwitch P2121 < 2.9.10
- DrayTek VigorSwitch PQ2121x < 2.9.10
- DrayTek VigorSwitch Q2121x < 2.9.10
- DrayTek VigorSwitch G2280x < 2.9.10
- DrayTek VigorSwitch P2280x < 2.9.10
- DrayTek VigorSwitch Q2200x < 2.9.10
- DrayTek VigorSwitch PQ2200xb < 2.9.10
- DrayTek VigorSwitch G2100 < 2.9.10
- DrayTek VigorSwitch P2100 < 2.9.10
- DrayTek VigorSwitch G2540x < 2.9.10
- DrayTek VigorSwitch P2540x < 2.9.10
Timeline
- 2026-08-24: disclosed: DrayTek security advisory DSA-2026-003 published
- 2026-08-24: patched: Fixed firmware versions released for all affected VigorSwitch models