Junglewise Threat Intelligence

CVE-2026-71936: DrayTek VigorSwitch buffer overflow in sysreboot function

CVE-2026-71936 · Severity: high · CVSS 7.2 · Published 2026-08-24

Technologies: DrayTek VigorSwitch PX2060, DrayTek VigorSwitch G2100, DrayTek VigorSwitch G2540xs, DrayTek VigorSwitch G1280, DrayTek VigorSwitch PQ2200xb, DrayTek VigorSwitch P2540xs, DrayTek VigorSwitch FX2120, DrayTek VigorSwitch P1280, DrayTek VigorSwitch P2121, DrayTek VigorSwitch P1281x, DrayTek VigorSwitch G2542x, DrayTek VigorSwitch Q2121x, DrayTek VigorSwitch PQ2300xb, DrayTek VigorSwitch G2540x, DrayTek VigorSwitch P2100, DrayTek VigorSwitch P2280x, DrayTek VigorSwitch G2121, DrayTek VigorSwitch Q2300x, DrayTek VigorSwitch P2542x, DrayTek VigorSwitch G2280x, DrayTek VigorSwitch PQ2121x, DrayTek VigorSwitch P2542xh, DrayTek VigorSwitch G1282, DrayTek VigorSwitch Q2200x, DrayTek VigorSwitch P2282x, DrayTek VigorSwitch P1282, DrayTek VigorSwitch G2282x, DrayTek VigorSwitch P2540x. Vendors: DrayTek.

Executive brief

DrayTek VigorSwitch is a network switch used in enterprise environments for traffic management and network connectivity. A buffer overflow vulnerability in the sysreboot function can be exploited by an authenticated administrator to cause denial of service or execute arbitrary code on the device. An attacker with valid admin credentials could gain full control of the switch, potentially disrupting network operations or accessing sensitive traffic passing through the device.

Technical details

The vulnerability is a classic buffer overflow (CWE-120) in the sysreboot function, caused by unsafe concatenation of split valueN parameters into a fixed-size buffer without proper bounds checking. The vulnerability is reachable only via the web management interface and requires valid administrative credentials to authenticate. Exploitation via crafted input can result in denial of service or arbitrary code execution on the affected appliance. Patches are available for all affected models, ranging from firmware version 2.9.10 to 3.10.6 depending on the specific VigorSwitch model.

Affected products

  • DrayTek VigorSwitch G2540xs < 3.9.10
  • DrayTek VigorSwitch P2540xs < 3.9.10
  • DrayTek VigorSwitch FX2120 < 3.9.10
  • DrayTek VigorSwitch G2282x < 2.10.6
  • DrayTek VigorSwitch P2282x < 2.10.6
  • DrayTek VigorSwitch Q2300x < 2.10.7
  • DrayTek VigorSwitch PQ2300xb < 2.10.7
  • DrayTek VigorSwitch G2542x < 3.10.6
  • DrayTek VigorSwitch P2542x < 3.10.6
  • DrayTek VigorSwitch P2542xh < 3.10.6
  • DrayTek VigorSwitch PX2060 < 2.9.10
  • DrayTek VigorSwitch G1280 < 2.9.10
  • DrayTek VigorSwitch P1280 < 2.9.10
  • DrayTek VigorSwitch P1281x < 2.9.10
  • DrayTek VigorSwitch G1282 < 2.9.10
  • DrayTek VigorSwitch P1282 < 2.9.10
  • DrayTek VigorSwitch G2121 < 2.9.10
  • DrayTek VigorSwitch P2121 < 2.9.10
  • DrayTek VigorSwitch PQ2121x < 2.9.10
  • DrayTek VigorSwitch Q2121x < 2.9.10
  • DrayTek VigorSwitch G2280x < 2.9.10
  • DrayTek VigorSwitch P2280x < 2.9.10
  • DrayTek VigorSwitch Q2200x < 2.9.10
  • DrayTek VigorSwitch PQ2200xb < 2.9.10
  • DrayTek VigorSwitch G2100 < 2.9.10
  • DrayTek VigorSwitch P2100 < 2.9.10
  • DrayTek VigorSwitch G2540x < 2.9.10
  • DrayTek VigorSwitch P2540x < 2.9.10

Timeline

  • 2026-08-24: disclosed

References

Related threats