Junglewise Threat Intelligence

CVE-2026-71935: DrayTek VigorSwitch buffer overflow in webBackupAction

CVE-2026-71935 · Severity: high · CVSS 7.2 · Published 2026-08-24

Technologies: DrayTek VigorSwitch PQ2200xb, DrayTek VigorSwitch PQ2121x, DrayTek VigorSwitch P2280x, DrayTek VigorSwitch PQ2300xb, DrayTek VigorSwitch G1280, DrayTek VigorSwitch P2540xs, DrayTek VigorSwitch FX2120, DrayTek VigorSwitch P2282x, DrayTek VigorSwitch G2121, DrayTek VigorSwitch P1280, DrayTek VigorSwitch P1282, DrayTek VigorSwitch Q2300x, DrayTek VigorSwitch P2100, DrayTek VigorSwitch Q2200x, DrayTek VigorSwitch G2282x, DrayTek VigorSwitch P2540x, DrayTek VigorSwitch G2100, DrayTek VigorSwitch G2540xs, DrayTek VigorSwitch G2540x, DrayTek VigorSwitch G1282, DrayTek VigorSwitch P1281x, DrayTek VigorSwitch P2542xh, DrayTek VigorSwitch P2542x, DrayTek VigorSwitch P2121, DrayTek VigorSwitch Q2121x, DrayTek VigorSwitch G2542x, DrayTek VigorSwitch PX2060, DrayTek VigorSwitch G2280x. Vendors: DrayTek.

Executive brief

DrayTek VigorSwitch series are managed network switches used to control enterprise network infrastructure. A buffer overflow vulnerability in the web management interface allows authenticated administrators to trigger memory corruption that could lead to denial of service or arbitrary code execution on the switch. Exploitation requires valid administrative credentials and network access to the device's web management port.

Technical details

The vulnerability is a classic stack-based buffer overflow (CWE-120) in the webBackupAction function of the mainfunction.cgi component. It occurs due to repeated string concatenation of pathN, valueN, key, and option fields into fixed-size stack buffers without total length validation. An authenticated attacker with web management access can supply crafted input via these parameters to overflow the buffer, potentially achieving arbitrary code execution or denial of service. The vulnerability requires valid administrative credentials and network connectivity to the switch's web management interface; no authentication bypass is needed. Patches are available across multiple VigorSwitch model families with various firmware versions (ranging from 2.9.10 to 3.10.6 depending on model).

Affected products

  • DrayTek VigorSwitch G2540xs < 3.9.10
  • DrayTek VigorSwitch P2540xs < 3.9.10
  • DrayTek VigorSwitch FX2120 < 3.9.10
  • DrayTek VigorSwitch G2282x < 2.10.6
  • DrayTek VigorSwitch P2282x < 2.10.6
  • DrayTek VigorSwitch Q2300x < 2.10.7
  • DrayTek VigorSwitch PQ2300xb < 2.10.7
  • DrayTek VigorSwitch G2542x < 3.10.6
  • DrayTek VigorSwitch P2542x < 3.10.6
  • DrayTek VigorSwitch P2542xh < 3.10.6
  • DrayTek VigorSwitch PX2060 < 2.9.10
  • DrayTek VigorSwitch G1280 < 2.9.10
  • DrayTek VigorSwitch P1280 < 2.9.10
  • DrayTek VigorSwitch P1281x < 2.9.10
  • DrayTek VigorSwitch G1282 < 2.9.10
  • DrayTek VigorSwitch P1282 < 2.9.10
  • DrayTek VigorSwitch G2121 < 2.9.10
  • DrayTek VigorSwitch P2121 < 2.9.10
  • DrayTek VigorSwitch PQ2121x < 2.9.10
  • DrayTek VigorSwitch Q2121x < 2.9.10
  • DrayTek VigorSwitch G2280x < 2.9.10
  • DrayTek VigorSwitch P2280x < 2.9.10
  • DrayTek VigorSwitch Q2200x < 2.9.10
  • DrayTek VigorSwitch PQ2200xb < 2.9.10
  • DrayTek VigorSwitch G2100 < 2.9.10
  • DrayTek VigorSwitch P2100 < 2.9.10
  • DrayTek VigorSwitch G2540x < 2.9.10
  • DrayTek VigorSwitch P2540x < 2.9.10

Timeline

  • 2026-08-24: disclosed
  • 2026-08-24: patched: Firmware updates released for affected models

References

Related threats