Junglewise Threat Intelligence

CVE-2026-71933: DrayTek VigorSwitch missing authorization in syslog functions

CVE-2026-71933 · Severity: critical · CVSS 9.1 · Published 2026-08-24

Technologies: DrayTek VigorSwitch PX2060, DrayTek VigorSwitch G2100, DrayTek VigorSwitch G2540xs, DrayTek VigorSwitch G1280, DrayTek VigorSwitch PQ2200xb, DrayTek VigorSwitch P2540xs, DrayTek VigorSwitch FX2120, DrayTek VigorSwitch P1280, DrayTek VigorSwitch P2121, DrayTek VigorSwitch P1281x, DrayTek VigorSwitch G2542x, DrayTek VigorSwitch Q2121x, DrayTek VigorSwitch PQ2300xb, DrayTek VigorSwitch G2540x, DrayTek VigorSwitch P2100, DrayTek VigorSwitch P2280x, DrayTek VigorSwitch G2121, DrayTek VigorSwitch Q2300x, DrayTek VigorSwitch P2542x, DrayTek VigorSwitch G2280x, DrayTek VigorSwitch PQ2121x, DrayTek VigorSwitch P2542xh, DrayTek VigorSwitch G1282, DrayTek VigorSwitch Q2200x, DrayTek VigorSwitch P2282x, DrayTek VigorSwitch P1282, DrayTek VigorSwitch G2282x, DrayTek VigorSwitch P2540x. Vendors: DrayTek.

Executive brief

DrayTek VigorSwitch network switches contain a missing authorization vulnerability in their syslog management functions. An unauthenticated remote attacker can modify switch configuration, restart critical services, save startup settings, or clear system logs without requiring valid credentials. This could allow attackers to disable logging to cover their tracks, disrupt network operations, or persist unauthorized changes to switch configuration.

Technical details

The vulnerability is a missing authorization check (CWE-862) in multiple syslog-related functions in the VigorSwitch web management interface. An attacker can send crafted requests to trigger operations such as configuration modification, service restart, startup configuration save, and log clearing without authentication or proper authorization validation. The attack is network-accessible and requires no user interaction or authentication. A successful exploit allows an attacker to perform administrative operations on the affected switch, including disabling security logging and modifying device settings. DrayTek has released patched firmware versions for affected models with specific version numbers provided (e.g., 3.9.10 for G2540xs/P2540xs, 2.10.6 for G2282x/P2282x).

Affected products

  • DrayTek VigorSwitch G2540xs < 3.9.10
  • DrayTek VigorSwitch P2540xs < 3.9.10
  • DrayTek VigorSwitch FX2120 < 3.9.10
  • DrayTek VigorSwitch G2282x < 2.10.6
  • DrayTek VigorSwitch P2282x < 2.10.6
  • DrayTek VigorSwitch Q2300x < 2.10.7
  • DrayTek VigorSwitch PQ2300xb < 2.10.7
  • DrayTek VigorSwitch G2542x < 3.10.6
  • DrayTek VigorSwitch P2542x < 3.10.6
  • DrayTek VigorSwitch P2542xh < 3.10.6
  • DrayTek VigorSwitch PX2060 < 2.9.10
  • DrayTek VigorSwitch G1280 < 2.9.10
  • DrayTek VigorSwitch P1280 < 2.9.10
  • DrayTek VigorSwitch P1281x < 2.9.10
  • DrayTek VigorSwitch G1282 < 2.9.10
  • DrayTek VigorSwitch P1282 < 2.9.10
  • DrayTek VigorSwitch G2121 < 2.9.10
  • DrayTek VigorSwitch P2121 < 2.9.10
  • DrayTek VigorSwitch PQ2121x < 2.9.10
  • DrayTek VigorSwitch Q2121x < 2.9.10
  • DrayTek VigorSwitch G2280x < 2.9.10
  • DrayTek VigorSwitch P2280x < 2.9.10
  • DrayTek VigorSwitch Q2200x < 2.9.10
  • DrayTek VigorSwitch PQ2200xb < 2.9.10
  • DrayTek VigorSwitch G2100 < 2.9.10
  • DrayTek VigorSwitch P2100 < 2.9.10
  • DrayTek VigorSwitch G2540x < 2.9.10
  • DrayTek VigorSwitch P2540x < 2.9.10

Timeline

  • 2026-08-24: disclosed
  • 2026-08-24: patched

References

Related threats