Junglewise Threat Intelligence

CVE-2026-71942: DrayTek VigorSwitch buffer overflow in mail_mailalert

CVE-2026-71942 · Severity: high · CVSS 7.2 · Published 2026-08-24

Technologies: DrayTek VigorSwitch PQ2200xb, DrayTek VigorSwitch PQ2121x, DrayTek VigorSwitch P2280x, DrayTek VigorSwitch PQ2300xb, DrayTek VigorSwitch G1280, DrayTek VigorSwitch P2540xs, DrayTek VigorSwitch FX2120, DrayTek VigorSwitch P2282x, DrayTek VigorSwitch G2121, DrayTek VigorSwitch P1280, DrayTek VigorSwitch P1282, DrayTek VigorSwitch Q2300x, DrayTek VigorSwitch P2100, DrayTek VigorSwitch Q2200x, DrayTek VigorSwitch G2282x, DrayTek VigorSwitch P2540x, DrayTek VigorSwitch G2100, DrayTek VigorSwitch G2540xs, DrayTek VigorSwitch G2540x, DrayTek VigorSwitch G1282, DrayTek VigorSwitch P1281x, DrayTek VigorSwitch P2542xh, DrayTek VigorSwitch P2542x, DrayTek VigorSwitch P2121, DrayTek VigorSwitch Q2121x, DrayTek VigorSwitch G2542x, DrayTek VigorSwitch PX2060, DrayTek VigorSwitch G2280x. Vendors: DrayTek.

Executive brief

DrayTek VigorSwitch is a managed network switch used in corporate environments to route and manage data traffic. A buffer overflow in the mail alert functionality allows authenticated administrators to trigger a denial of service or potentially execute arbitrary code on the device by sending specially crafted email configuration input. While this requires valid admin credentials, successful exploitation could give attackers complete control over network infrastructure.

Technical details

The vulnerability is a classic buffer overflow (CWE-120) in the mail_mailalert function of multiple VigorSwitch firmware versions. The flaw occurs when the device concatenates multiple SMTP receiver email addresses into a fixed-size buffer without validating the remaining buffer capacity. An authenticated remote attacker with administrative credentials can exploit this via the web management interface by providing oversized email address input, leading to stack corruption. This can result in denial of service or, with careful payload crafting, arbitrary code execution on the affected appliance. Patches have been released for all affected models as of August 2026.

Affected products

  • DrayTek VigorSwitch G2540xs before 3.9.10
  • DrayTek VigorSwitch P2540xs before 3.9.10
  • DrayTek VigorSwitch FX2120 before 3.9.10
  • DrayTek VigorSwitch G2282x before 2.10.6
  • DrayTek VigorSwitch P2282x before 2.10.6
  • DrayTek VigorSwitch Q2300x before 2.10.7
  • DrayTek VigorSwitch PQ2300xb before 2.10.7
  • DrayTek VigorSwitch G2542x before 3.10.6
  • DrayTek VigorSwitch P2542x before 3.10.6
  • DrayTek VigorSwitch P2542xh before 3.10.6
  • DrayTek VigorSwitch PX2060 before 2.9.10
  • DrayTek VigorSwitch G1280 before 2.9.10
  • DrayTek VigorSwitch P1280 before 2.9.10
  • DrayTek VigorSwitch P1281x before 2.9.10
  • DrayTek VigorSwitch G1282 before 2.9.10
  • DrayTek VigorSwitch P1282 before 2.9.10
  • DrayTek VigorSwitch G2121 before 2.9.10
  • DrayTek VigorSwitch P2121 before 2.9.10
  • DrayTek VigorSwitch PQ2121x before 2.9.10
  • DrayTek VigorSwitch Q2121x before 2.9.10
  • DrayTek VigorSwitch G2280x before 2.9.10
  • DrayTek VigorSwitch P2280x before 2.9.10
  • DrayTek VigorSwitch Q2200x before 2.9.10
  • DrayTek VigorSwitch PQ2200xb before 2.9.10
  • DrayTek VigorSwitch G2100 before 2.9.10
  • DrayTek VigorSwitch P2100 before 2.9.10
  • DrayTek VigorSwitch G2540x before 2.9.10
  • DrayTek VigorSwitch P2540x before 2.9.10

Timeline

  • 2026-08-24: disclosed
  • 2026-08-24: patched: Fixed firmware versions released for all affected models

References

Related threats