Draytek

Vigorswitch P2540xs

29 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 3.05%
  • Veröffentlicht 24.08.2026 17:08:06
  • Zuletzt bearbeitet 26.08.2026 17:17:13

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setDevNet function. The vulnerability is caused by insufficient filtering of the username and password fields before command execution. A remote attacker can trigger...

  • EPSS 0.48%
  • Veröffentlicht 24.08.2026 17:08:05
  • Zuletzt bearbeitet 26.08.2026 17:08:22

Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the mail_mailalert function. The vulnerability is caused by concatenating multiple smtpReceiver email addresses into a fixed-size buffer without checking the remaining buf...

  • EPSS 0.48%
  • Veröffentlicht 24.08.2026 17:08:04
  • Zuletzt bearbeitet 27.08.2026 17:19:49

Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the diag_logmail function. The vulnerability is caused by concatenating multiple smtpReceiver email addresses into a fixed-size buffer without checking the remaining buffe...

  • EPSS 0.48%
  • Veröffentlicht 24.08.2026 17:08:03
  • Zuletzt bearbeitet 26.08.2026 17:08:22

Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the acl_general_setup Edit ACE function. The vulnerability is caused by copying the name field into a fixed-size buffer without length validation. A remote attacker can tr...

  • EPSS 0.48%
  • Veröffentlicht 24.08.2026 17:08:03
  • Zuletzt bearbeitet 26.08.2026 17:08:22

Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the acl_general_setup Add ACE function. The vulnerability is caused by copying the name field into a fixed-size buffer without length validation. A remote attacker can tri...

  • EPSS 0.48%
  • Veröffentlicht 24.08.2026 17:08:02
  • Zuletzt bearbeitet 26.08.2026 17:17:13

Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the switch_lan_gvrp function. The vulnerability is caused by unsafe copying of the portList field into an undersized buffer. A remote attacker can trigger this vulnerabili...

  • EPSS 0.48%
  • Veröffentlicht 24.08.2026 17:08:01
  • Zuletzt bearbeitet 26.08.2026 17:08:22

Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the poe_schedule_profile function. The vulnerability is caused by repeated concatenation of the start_date, start_time, duration_time, how_often, weekdays, monthly_date, a...

  • EPSS 0.48%
  • Veröffentlicht 24.08.2026 17:08:01
  • Zuletzt bearbeitet 27.08.2026 17:19:49

Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the sysreboot function. The vulnerability is caused by unsafe concatenation of split valueN data into a fixed-size buffer. A remote attacker can trigger this vulnerability...

  • EPSS 0.48%
  • Veröffentlicht 24.08.2026 17:08:00
  • Zuletzt bearbeitet 26.08.2026 17:08:22

Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the webBackupAction function. The vulnerability is caused by repeated string concatenation of the pathN, valueN, key, and option fields into fixed-size stack buffers witho...

  • EPSS 0.48%
  • Veröffentlicht 24.08.2026 17:07:59
  • Zuletzt bearbeitet 26.08.2026 17:08:22

Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the pingtrace function. The vulnerability is caused by missing length checks when the host, count, and interval fields are concatenated into a fixed-size buffer. A remote ...