Junglewise Threat Intelligence

CVE-2026-71932: DrayTek VigorSwitch directory traversal in getSyslogFile

CVE-2026-71932 · Severity: medium · CVSS 4.9 · Published 2026-08-24

Technologies: DrayTek VigorSwitch PQ2200xb, DrayTek VigorSwitch PQ2121x, DrayTek VigorSwitch P2280x, DrayTek VigorSwitch PQ2300xb, DrayTek VigorSwitch G1280, DrayTek VigorSwitch P2540xs, DrayTek VigorSwitch FX2120, DrayTek VigorSwitch P2282x, DrayTek VigorSwitch G2121, DrayTek VigorSwitch P1280, DrayTek VigorSwitch P1282, DrayTek VigorSwitch Q2300x, DrayTek VigorSwitch P2100, DrayTek VigorSwitch Q2200x, DrayTek VigorSwitch G2282x, DrayTek VigorSwitch P2540x, DrayTek VigorSwitch G2100, DrayTek VigorSwitch G2540xs, DrayTek VigorSwitch G2540x, DrayTek VigorSwitch G1282, DrayTek VigorSwitch P1281x, DrayTek VigorSwitch P2542xh, DrayTek VigorSwitch P2542x, DrayTek VigorSwitch P2121, DrayTek VigorSwitch Q2121x, DrayTek VigorSwitch G2542x, DrayTek VigorSwitch PX2060, DrayTek VigorSwitch G2280x. Vendors: DrayTek.

Executive brief

DrayTek VigorSwitch is a network switch used to manage enterprise network traffic. The getSyslogFile function contains a directory traversal vulnerability that allows an authenticated administrator to access arbitrary files on the device by providing crafted input with path traversal sequences. While this requires valid admin credentials, a compromised or malicious administrator account could read sensitive configuration files, logs, or other data stored on the switch.

Technical details

The vulnerability is a path traversal (CWE-22) in the getSyslogFile function within the mainfunction.cgi component of DrayTek VigorSwitch. The root cause is insufficient validation of the option field, which allows an attacker to inject path traversal sequences (e.g., ../) to read arbitrary files outside the intended directory. Attack requires valid administrative credentials and network access to the device's web management interface; no direct remote unauthenticated exploitation is possible. Successful exploitation allows reading sensitive files but does not grant code execution or write access. DrayTek has released patched firmware versions for all affected models, with version numbers varying by model (e.g., 3.9.10 for G2540xs/P2540xs, 2.9.10 for G1280/P1280).

Affected products

  • DrayTek VigorSwitch G2540xs before 3.9.10
  • DrayTek VigorSwitch P2540xs before 3.9.10
  • DrayTek VigorSwitch FX2120 before 3.9.10
  • DrayTek VigorSwitch G2282x before 2.10.6
  • DrayTek VigorSwitch P2282x before 2.10.6
  • DrayTek VigorSwitch Q2300x before 2.10.7
  • DrayTek VigorSwitch PQ2300xb before 2.10.7
  • DrayTek VigorSwitch G2542x before 3.10.6
  • DrayTek VigorSwitch P2542x before 3.10.6
  • DrayTek VigorSwitch P2542xh before 3.10.6
  • DrayTek VigorSwitch PX2060 before 2.9.10
  • DrayTek VigorSwitch G1280 before 2.9.10
  • DrayTek VigorSwitch P1280 before 2.9.10
  • DrayTek VigorSwitch P1281x before 2.9.10
  • DrayTek VigorSwitch G1282 before 2.9.10
  • DrayTek VigorSwitch P1282 before 2.9.10
  • DrayTek VigorSwitch G2121 before 2.9.10
  • DrayTek VigorSwitch P2121 before 2.9.10
  • DrayTek VigorSwitch PQ2121x before 2.9.10
  • DrayTek VigorSwitch Q2121x before 2.9.10
  • DrayTek VigorSwitch G2280x before 2.9.10
  • DrayTek VigorSwitch P2280x before 2.9.10
  • DrayTek VigorSwitch Q2200x before 2.9.10
  • DrayTek VigorSwitch PQ2200xb before 2.9.10
  • DrayTek VigorSwitch G2100 before 2.9.10
  • DrayTek VigorSwitch P2100 before 2.9.10
  • DrayTek VigorSwitch G2540x before 2.9.10
  • DrayTek VigorSwitch P2540x before 2.9.10

Timeline

  • 2026-08-24: disclosed

References

Related threats