VDB
GCVE-110-NCSC-2026-328
GCVE-110-NCSC-2026-328
Advisory PublishedCVSS 9.1/10
Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the jsonstatus function that permits remote attackers with valid admin credentials to execute arbitrary commands with root privileges due to insufficient input filtering.
Weaknesses (CWE)
CWE-78Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')CWE-476NULL Pointer DereferenceCWE-22Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')CWE-862Missing AuthorizationCWE-120Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Risk Scores
CVSS 3.1
9.1/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| DrayTek Corporation | vers:unknown/* | — | — |
| DrayTek | vers:unknown/* | — | — |
Aliases
CVE-2026-71915CVE-2026-71916CVE-2026-71917CVE-2026-71918CVE-2026-71919CVE-2026-71920CVE-2026-71921CVE-2026-71922CVE-2026-71923CVE-2026-71924CVE-2026-71925CVE-2026-71926CVE-2026-71927CVE-2026-71928CVE-2026-71929CVE-2026-71930CVE-2026-71931CVE-2026-71932CVE-2026-71933CVE-2026-71934CVE-2026-71935CVE-2026-71936CVE-2026-71937CVE-2026-71938CVE-2026-71939CVE-2026-71940CVE-2026-71941CVE-2026-71942CVE-2026-71943
References
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.