VDB
CVE-2026-71921
CVE-2026-71921
PUBLISHED
CVSS 9.3 CRITICAL
Reported by VulnCheck · Published August 24, 2026
Multiple DrayTek VigorSwitch models contain a pre-authentication command injection vulnerability in the setget.cgi interface. The vulnerability is caused by insufficient filtering of the pass field before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges.
Risk Scores
CVSS 4.0
9.3
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| DrayTek Corporation | VigorSwitch G2540xs | 0 |
| DrayTek Corporation | VigorSwitch P2540xs | 0 |
| DrayTek Corporation | VigorSwitch FX2120 | 0 |
| DrayTek Corporation | VigorSwitch G2282x | 0 |
| DrayTek Corporation | VigorSwitch P2282x | 0 |
| DrayTek Corporation | VigorSwitch Q2300x | 0 |
| DrayTek Corporation | VigorSwitch PQ2300xb | 0 |
| DrayTek Corporation | VigorSwitch G2542x | 0 |
| DrayTek Corporation | VigorSwitch P2542x | 0 |
| DrayTek Corporation | VigorSwitch P2542xh | 0 |
| DrayTek Corporation | VigorSwitch PX2060 | 0 |
| DrayTek Corporation | VigorSwitch G1280 | 0 |
| DrayTek Corporation | VigorSwitch P1280 | 0 |
| DrayTek Corporation | VigorSwitch P1281x | 0 |
| DrayTek Corporation | VigorSwitch G1282 | 0 |
| DrayTek Corporation | VigorSwitch P1282 | 0 |
| DrayTek Corporation | VigorSwitch G2121 | 0 |
| DrayTek Corporation | VigorSwitch P2121 | 0 |
| DrayTek Corporation | VigorSwitch PQ2121x | 0 |
| DrayTek Corporation | VigorSwitch Q2121x | 0 |
…and 50 more
Timeline
- Aug 24, 2026 Coalition ESS Score
- Aug 24, 2026 CVE Published
- Aug 25, 2026 EPSS Score
- Sep 4, 2026 EPSS Score
References
- vendor-advisory
- VulnCheck Advisory: DrayTek VigorSwitch Multiple Models Pre-Authentication OS Command Injection via setget.cgi third-party-advisory