CVE-2026-71933
- EPSS 0.38%
- Veröffentlicht 24.08.2026 17:07:59
- Zuletzt bearbeitet 26.08.2026 17:17:13
Multiple DrayTek VigorSwitch models contain unauthorized operation vulnerabilities in multiple syslog functions. The vulnerability is caused by missing authorization checks. A remote attacker can trigger these vulnerabilities via crafted requests to ...
CVE-2026-71932
- EPSS 0.69%
- Veröffentlicht 24.08.2026 17:07:58
- Zuletzt bearbeitet 26.08.2026 17:08:22
Multiple DrayTek VigorSwitch models contain a directory traversal vulnerability in the getSyslogFile function. The vulnerability is caused by insufficient validation of the option field. A remote attacker can trigger this vulnerability via crafted in...
CVE-2026-71931
- EPSS 2.41%
- Veröffentlicht 24.08.2026 17:07:57
- Zuletzt bearbeitet 27.08.2026 17:19:48
Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the tftp_upgrade function. The vulnerability is caused by insufficient filtering before the filename field is concatenated into a command. A remote attacker can trigger ...
CVE-2026-71929
- EPSS 3.05%
- Veröffentlicht 24.08.2026 17:07:56
- Zuletzt bearbeitet 26.08.2026 17:08:22
Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setDevProto function. The vulnerability is caused by insufficient filtering of the username and password fields before command execution. A remote attacker can trigg...
CVE-2026-71930
- EPSS 3.05%
- Veröffentlicht 24.08.2026 17:07:56
- Zuletzt bearbeitet 26.08.2026 17:08:22
Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setTime function. The vulnerability is caused by insufficient filtering of the username and password fields before command execution. A remote attacker can trigger t...
CVE-2026-71928
- EPSS 1.67%
- Veröffentlicht 24.08.2026 17:07:55
- Zuletzt bearbeitet 26.08.2026 17:17:12
Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the fdftDevice function. The vulnerability is caused by insufficient filtering of the username and password fields before command execution. A remote attacker can trigge...
CVE-2026-71927
- EPSS 1.67%
- Veröffentlicht 24.08.2026 17:07:54
- Zuletzt bearbeitet 26.08.2026 17:08:22
Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the rebDevice function. The vulnerability is caused by insufficient filtering of the username and password fields before command execution. A remote attacker can trigger...
CVE-2026-71926
- EPSS 1.67%
- Veröffentlicht 24.08.2026 17:07:54
- Zuletzt bearbeitet 27.08.2026 17:19:48
Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setDevice function. The vulnerability is caused by insufficient sanitization of the username, password, and location fields before command execution. A remote attack...
CVE-2026-71925
- EPSS 3.05%
- Veröffentlicht 24.08.2026 17:07:53
- Zuletzt bearbeitet 26.08.2026 17:08:22
Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the getDetail function. The vulnerability is caused by insufficient filtering of the username and password fields before command execution. A remote attacker can trigger...
CVE-2026-71924
- EPSS 3.05%
- Veröffentlicht 24.08.2026 17:07:52
- Zuletzt bearbeitet 26.08.2026 17:08:22
Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the getVid function. The vulnerability is caused by insufficient filtering of the username and password fields before command execution. A remote attacker can trigger th...