Multiple DrayTek VigorAP models contain a command injection vulnerability in the setLan function. The vulnerability is caused by insufficient validation of the lanIp and lanNetmask fields before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administrative credentials for the device's web management interface.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Draytek
Subscribe
|
Vigorap 1060c
Subscribe
Vigorap 1060c Firmware
Subscribe
Vigorap 903
Subscribe
Vigorap 903 Firmware
Subscribe
Vigorap 906
Subscribe
Vigorap 906 Firmware
Subscribe
Vigorap 912c
Subscribe
Vigorap 912c Firmware
Subscribe
Vigorap 918r
Subscribe
Vigorap 918r Firmware
Subscribe
Vigorap 960c
Subscribe
Vigorap 960c Firmware
Subscribe
|
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 24 Aug 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Draytek vigorap 1060c
Draytek vigorap 903 Draytek vigorap 906 Draytek vigorap 912c Draytek vigorap 918r Draytek vigorap 960c |
|
| Vendors & Products |
Draytek vigorap 1060c
Draytek vigorap 903 Draytek vigorap 906 Draytek vigorap 912c Draytek vigorap 918r Draytek vigorap 960c |
Mon, 24 Aug 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Multiple DrayTek VigorAP models contain a command injection vulnerability in the setLan function. The vulnerability is caused by insufficient validation of the lanIp and lanNetmask fields before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administrative credentials for the device's web management interface. | |
| Title | DrayTek VigorAP Multiple Models OS Command Injection via setLan | |
| First Time appeared |
Draytek
Draytek vigorap 1060c Firmware Draytek vigorap 903 Firmware Draytek vigorap 906 Firmware Draytek vigorap 912c Firmware Draytek vigorap 918r Firmware Draytek vigorap 960c Firmware |
|
| Weaknesses | CWE-78 | |
| CPEs | cpe:2.3:o:draytek:vigorap_1060c_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:draytek:vigorap_903_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:draytek:vigorap_906_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:draytek:vigorap_912c_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:draytek:vigorap_918r_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:draytek:vigorap_960c_firmware:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Draytek
Draytek vigorap 1060c Firmware Draytek vigorap 903 Firmware Draytek vigorap 906 Firmware Draytek vigorap 912c Firmware Draytek vigorap 918r Firmware Draytek vigorap 960c Firmware |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-24T17:07:40.927Z
Reserved: 2026-08-08T16:37:44.517Z
Link: CVE-2026-71906
No data.
Status : Received
Published: 2026-08-24T18:17:02.067
Modified: 2026-08-24T18:17:02.067
Link: CVE-2026-71906
No data.
OpenCVE Enrichment
Updated: 2026-08-24T19:00:05Z
Weaknesses