Vendor
DrayTek vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 46 vulnerabilities in DrayTek: 0 in the last 7 days and 40 in the last 90 days, 8 of them critical and 5 exploited in the wild. The most recent, CVE-2026-71943, was published on 24 August 2026. 34 technologies have a page of their own.
- Last 7 days
- 0
- Last 90 days
- 40
- Critical, all time
- 8
- Exploited in the wild
- 5
About DrayTek
A manufacturer of networking equipment including routers, firewalls, and wireless access points.
DrayTek technologies
- DrayTek VigorSwitch FX212029
- DrayTek VigorSwitch G128029
- DrayTek VigorSwitch G128229
- DrayTek VigorSwitch G210029
- DrayTek VigorSwitch G212129
- DrayTek VigorSwitch G2280x29
- DrayTek VigorSwitch G2282x29
- DrayTek VigorSwitch G2540x29
- DrayTek VigorSwitch G2540xs29
- DrayTek VigorSwitch G2542x29
- DrayTek VigorSwitch P128029
- DrayTek VigorSwitch P1281x29
- DrayTek VigorSwitch P128229
- DrayTek VigorSwitch P210029
- DrayTek VigorSwitch P212129
- DrayTek VigorSwitch P2280x29
- DrayTek VigorSwitch P2282x29
- DrayTek VigorSwitch P2540x29
- DrayTek VigorSwitch P2540xs29
- DrayTek VigorSwitch P2542x29
- DrayTek VigorSwitch P2542xh29
- DrayTek VigorSwitch PQ2121x29
- DrayTek VigorSwitch PQ2200xb29
- DrayTek VigorSwitch PQ2300xb29
- DrayTek VigorSwitch PX206029
- DrayTek VigorSwitch Q2121x29
- DrayTek VigorSwitch Q2200x29
- DrayTek VigorSwitch Q2300x29
- DrayTek VigorAP 90312
- DrayTek VigorAP 912C12
- DrayTek VigorAP 918R12
- DrayTek VigorAP 1060C11
- DrayTek VigorAP 90611
- DrayTek VigorAP 960C11
Latest DrayTek vulnerabilities
- CVE-2026-71943: DrayTek VigorSwitch command injection in setDevNethighCVSS 7.2EPSS 2.3%
- CVE-2026-71942: DrayTek VigorSwitch buffer overflow in mail_mailalerthighCVSS 7.2EPSS 0.7%
- CVE-2026-71941: DrayTek VigorSwitch buffer overflow in diag_logmailhighCVSS 7.2EPSS 0.7%
- CVE-2026-71940: DrayTek VigorSwitch buffer overflow in acl_general_setup Edit ACEhighCVSS 7.2EPSS 0.7%
- CVE-2026-71939: DrayTek VigorSwitch buffer overflow in acl_general_setuphighCVSS 7.2EPSS 0.7%
- CVE-2026-71938: DrayTek VigorSwitch buffer overflow in switch_lan_gvrphighCVSS 7.2EPSS 0.7%
- CVE-2026-71937: DrayTek VigorSwitch buffer overflow in poe_schedule_profilehighCVSS 7.2EPSS 0.7%
- CVE-2026-71936: DrayTek VigorSwitch buffer overflow in sysreboot functionhighCVSS 7.2EPSS 0.7%
- CVE-2026-71935: DrayTek VigorSwitch buffer overflow in webBackupActionhighCVSS 7.2EPSS 0.7%
- CVE-2026-71934: DrayTek VigorSwitch buffer overflow in pingtracehighCVSS 7.2EPSS 0.7%
- CVE-2026-71933: DrayTek VigorSwitch missing authorization in syslog functionscriticalCVSS 9.1EPSS 0.5%
- CVE-2026-71932: DrayTek VigorSwitch directory traversal in getSyslogFilemediumCVSS 4.9EPSS 1.0%
- CVE-2026-71931: DrayTek VigorSwitch command injection in tftp_upgradehighCVSS 7.2EPSS 1.8%
- CVE-2026-71930: DrayTek VigorSwitch command injection in setTime functionhighCVSS 7.2EPSS 2.3%
- CVE-2026-71929: DrayTek VigorSwitch command injection in setDevProtohighCVSS 7.2EPSS 2.3%
- CVE-2026-71928: DrayTek VigorSwitch command injection in fdftDevicehighCVSS 7.2EPSS 2.3%
- CVE-2026-71927: DrayTek VigorSwitch command injection in rebDevicehighCVSS 7.2EPSS 2.3%
- CVE-2026-71926: DrayTek VigorSwitch command injection in setDevicehighCVSS 7.2EPSS 2.3%
- CVE-2026-71925: DrayTek VigorSwitch command injection in getDetailhighCVSS 7.2EPSS 2.3%
- CVE-2026-71924: DrayTek VigorSwitch command injection in getVid functionhighCVSS 7.2EPSS 2.3%
- CVE-2026-71923: DrayTek VigorSwitch command injection in auth_set functionhighCVSS 7.2EPSS 2.3%
- CVE-2026-71922: DrayTek VigorSwitch null pointer dereference in setget.cgihighCVSS 7.5EPSS 0.7%
- CVE-2026-71921: DrayTek VigorSwitch pre-authentication command injection in setget.cgicriticalCVSS 9.8EPSS 2.8%
- CVE-2026-71920: DrayTek VigorSwitch null pointer dereference in formlogoutmediumCVSS 4.9EPSS 0.6%
- CVE-2026-71919: DrayTek VigorSwitch command injection in sysreboothighCVSS 7.2EPSS 2.3%
Most severe DrayTek vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2024-12987: DrayTek Vigor Routers OS Command Injection Vulnerabilitycriticalexploited in the wildCVSS 9.8
- CVE-2020-15415: DrayTek Multiple Vigor Routers OS Command Injection Vulnerabilitycriticalexploited in the wildCVSS 9.8
- CVE-2020-8515: Multiple DrayTek Vigor Routers Web Management Page Vulnerabilitycriticalexploited in the wildCVSS 9.8
- CVE-2021-20123: Draytek VigorConnect Path Traversal Vulnerabilitycriticalexploited in the wildCVSS 7.5
- CVE-2021-20124: Draytek VigorConnect Path Traversal Vulnerabilitycriticalexploited in the wildCVSS 7.5
- CVE-2026-71921: DrayTek VigorSwitch pre-authentication command injection in setget.cgicriticalCVSS 9.8EPSS 2.8%
- CVE-2026-71914: DrayTek VigorAP command injection in dray_apmcriticalCVSS 9.8EPSS 2.6%
- CVE-2026-71933: DrayTek VigorSwitch missing authorization in syslog functionscriticalCVSS 9.1EPSS 0.5%
- CVE-2025-44643: DrayTek VigorAP hardcoded weak password in ripd.confhighCVSS 8.6EPSS 0.3%
- CVE-2026-71922: DrayTek VigorSwitch null pointer dereference in setget.cgihighCVSS 7.5EPSS 0.7%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 40 | 3 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/draytek.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "DrayTek vulnerabilities", https://junglewise.ai/threats/vendors/draytek, 26 September 2026.