CVE-2026-71923
- EPSS 1.67%
- Veröffentlicht 24.08.2026 17:07:52
- Zuletzt bearbeitet 26.08.2026 17:17:12
Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the auth_set function. The vulnerability is caused by insufficient filtering of the username and password fields before command execution. A remote attacker can trigger ...
CVE-2026-71922
- EPSS 0.47%
- Veröffentlicht 24.08.2026 17:07:51
- Zuletzt bearbeitet 26.08.2026 17:08:22
Multiple DrayTek VigorSwitch models contain a pre-authentication null pointer dereference vulnerability in the setget.cgi interface. The vulnerability is caused by missing validation when the pass field is absent. A remote attacker can trigger this v...
CVE-2026-71921
- EPSS 3.25%
- Veröffentlicht 24.08.2026 17:07:50
- Zuletzt bearbeitet 27.08.2026 17:19:47
Multiple DrayTek VigorSwitch models contain a pre-authentication command injection vulnerability in the setget.cgi interface. The vulnerability is caused by insufficient filtering of the pass field before command execution. A remote attacker can trig...
CVE-2026-71920
- EPSS 0.39%
- Veröffentlicht 24.08.2026 17:07:50
- Zuletzt bearbeitet 26.08.2026 17:08:22
Multiple DrayTek VigorSwitch models contain a null pointer dereference vulnerability in the formlogout function. The vulnerability is caused by missing checks for an empty or absent Cookie header before string handling. A remote attacker can trigger ...
CVE-2026-71919
- EPSS 3.05%
- Veröffentlicht 24.08.2026 17:07:49
- Zuletzt bearbeitet 26.08.2026 17:10:09
Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the sysreboot function. The vulnerability is caused by insufficient filtering of the config, act, pathN, and valueN fields before command execution. A remote attacker ca...
CVE-2026-71918
- EPSS 3.05%
- Veröffentlicht 24.08.2026 17:07:48
- Zuletzt bearbeitet 26.08.2026 17:17:12
Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the webBackupAction function. The vulnerability is caused by insufficient filtering of the option, key, pw_encode, pathN, and valueN fields before command execution. A r...
CVE-2026-71917
- EPSS 3.05%
- Veröffentlicht 24.08.2026 17:07:48
- Zuletzt bearbeitet 26.08.2026 17:10:09
Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the pingtrace function. The vulnerability is caused by insufficient validation of the host field before command execution. A remote attacker can trigger this vulnerabili...
CVE-2026-71916
- EPSS 2.41%
- Veröffentlicht 24.08.2026 17:07:47
- Zuletzt bearbeitet 27.08.2026 17:19:47
Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the commandTable function. The vulnerability is caused by incomplete filtering of dangerous characters such as backticks, newline characters, and single quotes in the pa...
CVE-2026-71915
- EPSS 3.05%
- Veröffentlicht 24.08.2026 17:07:46
- Zuletzt bearbeitet 26.08.2026 17:10:09
Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the jsonstatus function. The vulnerability is caused by insufficient filtering of the usescript, usefile, and option fields before command execution. A remote attacker c...