CVE-2026-71914
- EPSS 3.07%
- Veröffentlicht 24.08.2026 17:07:46
- Zuletzt bearbeitet 26.08.2026 17:10:09
Multiple DrayTek VigorAP models contain a command injection vulnerability in the dray_apm component. The vulnerability is caused by insufficient validation of UDP message content after START_SPEED_TEST before command execution. A remote attacker can ...
CVE-2026-71913
- EPSS 2.41%
- Veröffentlicht 24.08.2026 17:07:45
- Zuletzt bearbeitet 26.08.2026 17:17:12
Multiple DrayTek VigorAP models contain a command injection vulnerability in the upload_settings.cgi interface. The vulnerability is caused by insufficient filtering before the restorekey field is concatenated into a shell command. A remote attacker ...
CVE-2026-71911
- EPSS 0.48%
- Veröffentlicht 24.08.2026 17:07:44
- Zuletzt bearbeitet 26.08.2026 19:16:59
Multiple DrayTek VigorAP models contain a buffer overflow vulnerability in the setLan function. The vulnerability is caused by missing length checks during memory copy operations involving the lanVlanId0, lanIp, and lanNetmask fields. A remote attack...
CVE-2026-71912
- EPSS 0.48%
- Veröffentlicht 24.08.2026 17:07:44
- Zuletzt bearbeitet 26.08.2026 17:10:09
Multiple DrayTek VigorAP models contain a buffer overflow vulnerability in the apautotest function. The vulnerability is caused by missing length checks during memory copy operations involving the CMD6 field. A remote attacker can trigger this vulner...
CVE-2026-71910
- EPSS 3.05%
- Veröffentlicht 24.08.2026 17:07:43
- Zuletzt bearbeitet 26.08.2026 17:10:09
Multiple DrayTek VigorAP models contain a command injection vulnerability in the apautotest function. The vulnerability is caused by insufficient validation of the CMD0, CMD3, and CMD6 fields before command execution. A remote attacker can trigger th...
CVE-2026-71908
- EPSS 3.05%
- Veröffentlicht 24.08.2026 17:07:42
- Zuletzt bearbeitet 26.08.2026 17:17:12
Multiple DrayTek VigorAP models contain a command injection vulnerability in the mesh_start_speed_test function. The vulnerability is caused by insufficient sanitization of the meshdevice_index and meshdevice_ip fields before command execution. A rem...
CVE-2026-71909
- EPSS 3.05%
- Veröffentlicht 24.08.2026 17:07:42
- Zuletzt bearbeitet 26.08.2026 17:10:09
Multiple DrayTek VigorAP models contain a command injection vulnerability in the InquierTime function. The vulnerability is caused by insufficient filtering of the time field before command execution. A remote attacker can trigger this vulnerability ...
CVE-2026-71907
- EPSS 3.05%
- Veröffentlicht 24.08.2026 17:07:41
- Zuletzt bearbeitet 26.08.2026 17:10:09
Multiple DrayTek VigorAP models contain a command injection vulnerability in the setcamset function. The vulnerability is caused by insufficient filtering of the selectSlaves field before command execution. A remote attacker can trigger this vulnerab...
CVE-2026-71905
- EPSS 3.05%
- Veröffentlicht 24.08.2026 17:07:40
- Zuletzt bearbeitet 26.08.2026 17:32:25
Multiple DrayTek VigorAP models contain a command injection vulnerability in the ExportSettings function. The vulnerability is caused by insufficient filtering of the backupkey, backuptype, and realtime fields before command execution. A remote attac...
CVE-2026-71906
- EPSS 3.05%
- Veröffentlicht 24.08.2026 17:07:40
- Zuletzt bearbeitet 26.08.2026 19:16:58
Multiple DrayTek VigorAP models contain a command injection vulnerability in the setLan function. The vulnerability is caused by insufficient validation of the lanIp and lanNetmask fields before command execution. A remote attacker can trigger this v...