VDB

GCVE-110-NCSC-2026-327

GCVE-110-NCSC-2026-327
Advisory PublishedCVSS 9.8/10
Vulnetix · Advisory published August 26, 2026
Multiple DrayTek VigorAP models contain a command injection vulnerability in the tr069TestInform function that permits remote attackers with valid admin credentials to execute arbitrary commands with root privileges due to insufficient input filtering.

Weaknesses (CWE)

CWE-78Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')CWE-120Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

Risk Scores

CVSS 3.1
9.8/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
Draytekvers:unknown/*
DrayTekvers:unknown/*

References

advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory

Browse GCVE Records

867 records in the GCVE database · Updated September 2, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›