VDB
CVE-2026-71934
CVE-2026-71934
PUBLISHED
CVSS 8.6 HIGH
Reported by VulnCheck · Published August 24, 2026
Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the pingtrace function. The vulnerability is caused by missing length checks when the host, count, and interval fields are concatenated into a fixed-size buffer. A remote attacker can trigger this vulnerability via crafted input, causing a denial of service or potentially executing arbitrary commands. Exploitation requires valid administrative credentials for the device's web management interface.
Risk Scores
CVSS 4.0
8.6
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| DrayTek Corporation | VigorSwitch G2540xs | 0 |
| DrayTek Corporation | VigorSwitch P2540xs | 0 |
| DrayTek Corporation | VigorSwitch FX2120 | 0 |
| DrayTek Corporation | VigorSwitch G2282x | 0 |
| DrayTek Corporation | VigorSwitch P2282x | 0 |
| DrayTek Corporation | VigorSwitch Q2300x | 0 |
| DrayTek Corporation | VigorSwitch PQ2300xb | 0 |
| DrayTek Corporation | VigorSwitch G2542x | 0 |
| DrayTek Corporation | VigorSwitch P2542x | 0 |
| DrayTek Corporation | VigorSwitch P2542xh | 0 |
| DrayTek Corporation | VigorSwitch PX2060 | 0 |
| DrayTek Corporation | VigorSwitch G1280 | 0 |
| DrayTek Corporation | VigorSwitch P1280 | 0 |
| DrayTek Corporation | VigorSwitch P1281x | 0 |
| DrayTek Corporation | VigorSwitch G1282 | 0 |
| DrayTek Corporation | VigorSwitch P1282 | 0 |
| DrayTek Corporation | VigorSwitch G2121 | 0 |
| DrayTek Corporation | VigorSwitch P2121 | 0 |
| DrayTek Corporation | VigorSwitch PQ2121x | 0 |
| DrayTek Corporation | VigorSwitch Q2121x | 0 |
…and 50 more
Timeline
- Aug 24, 2026 Coalition ESS Score
- Aug 24, 2026 CVE Published
- Aug 25, 2026 EPSS Score
- Aug 26, 2026 CVE Updated
- Aug 27, 2026 EPSS Score
- Aug 31, 2026 EPSS Score
- Sep 3, 2026 EPSS Score
References
- vendor-advisory
- VulnCheck Advisory: DrayTek VigorSwitch Multiple Models Buffer Overflow via pingtrace third-party-advisory