Draytek

Vigorswitch G2540xs

29 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.67%
  • Veröffentlicht 24.08.2026 17:07:52
  • Zuletzt bearbeitet 26.08.2026 17:17:12

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the auth_set function. The vulnerability is caused by insufficient filtering of the username and password fields before command execution. A remote attacker can trigger ...

  • EPSS 0.47%
  • Veröffentlicht 24.08.2026 17:07:51
  • Zuletzt bearbeitet 26.08.2026 17:08:22

Multiple DrayTek VigorSwitch models contain a pre-authentication null pointer dereference vulnerability in the setget.cgi interface. The vulnerability is caused by missing validation when the pass field is absent. A remote attacker can trigger this v...

  • EPSS 3.25%
  • Veröffentlicht 24.08.2026 17:07:50
  • Zuletzt bearbeitet 27.08.2026 17:19:47

Multiple DrayTek VigorSwitch models contain a pre-authentication command injection vulnerability in the setget.cgi interface. The vulnerability is caused by insufficient filtering of the pass field before command execution. A remote attacker can trig...

  • EPSS 0.39%
  • Veröffentlicht 24.08.2026 17:07:50
  • Zuletzt bearbeitet 26.08.2026 17:08:22

Multiple DrayTek VigorSwitch models contain a null pointer dereference vulnerability in the formlogout function. The vulnerability is caused by missing checks for an empty or absent Cookie header before string handling. A remote attacker can trigger ...

  • EPSS 3.05%
  • Veröffentlicht 24.08.2026 17:07:49
  • Zuletzt bearbeitet 26.08.2026 17:10:09

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the sysreboot function. The vulnerability is caused by insufficient filtering of the config, act, pathN, and valueN fields before command execution. A remote attacker ca...

  • EPSS 3.05%
  • Veröffentlicht 24.08.2026 17:07:48
  • Zuletzt bearbeitet 26.08.2026 17:17:12

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the webBackupAction function. The vulnerability is caused by insufficient filtering of the option, key, pw_encode, pathN, and valueN fields before command execution. A r...

  • EPSS 3.05%
  • Veröffentlicht 24.08.2026 17:07:48
  • Zuletzt bearbeitet 26.08.2026 17:10:09

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the pingtrace function. The vulnerability is caused by insufficient validation of the host field before command execution. A remote attacker can trigger this vulnerabili...

  • EPSS 2.41%
  • Veröffentlicht 24.08.2026 17:07:47
  • Zuletzt bearbeitet 27.08.2026 17:19:47

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the commandTable function. The vulnerability is caused by incomplete filtering of dangerous characters such as backticks, newline characters, and single quotes in the pa...

  • EPSS 3.05%
  • Veröffentlicht 24.08.2026 17:07:46
  • Zuletzt bearbeitet 26.08.2026 17:10:09

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the jsonstatus function. The vulnerability is caused by insufficient filtering of the usescript, usefile, and option fields before command execution. A remote attacker c...