Multiple Remote Code Execution and Buffer Overflow Vulnerabilities in VigorAP Series
Number: DSA-2026-002
On June 1, several potential security vulnerabilities were identified within the DrayTek VigorAP, including buffer overflow conditions and improper neutralization of special elements used in operating system commands.
Several vulnerabilities have been identified in the affected code. At the time of publication, DrayTek is not aware of any successful exploitation methods or active attacks targeting these vulnerabilities. Consequently, there is no evidence at this time that the reported issues are exploitable in deployed environments. If a viable exploitation method were identified, it would likely require an attacker to possess valid administrative credentials and be able to authenticate to the VigorAP's web management interface.
Should a method be identified that allows these conditions to be reached and successfully exploited, they could potentially result in arbitrary code execution on an affected appliance. However, the feasibility of such exploitation has not been demonstrated. DrayTek Corp has addressed these findings in updated firmware releases and recommends that customers upgrade to the versions listed below as a preventive security measure.
Vulnerability Details
| CVE Number | Description |
|---|---|
| CVE-2026-71904 | OS Command Injection Flaws |
| CVE-2026-71905 | OS Command Injection Flaws |
| CVE-2026-71906 | OS Command Injection Flaws |
| CVE-2026-71907 | OS Command Injection Flaws |
| CVE-2026-71908 | OS Command Injection Flaws |
| CVE-2026-71909 | OS Command Injection Flaws |
| CVE-2026-71910 | OS Command Injection Flaws |
| CVE-2026-71911 | Buffer Overflow and OS Command Injection Flaws |
| CVE-2026-71912 | Buffer Overflow and OS Command Injection Flaws |
| CVE-2026-71913 | OS Command Injection Flaws |
| CVE-2026-71914 | OS Command Injection Flaws |
The firmware updates are released for the following models. No other models are affected. Please click here to download and upgrade the firmware for your specific model as soon as possible to ensure your system remains up to date.
Affected Products and Recommended Firmware Versions
| Model | Fixed Firmware Version |
|---|---|
| VigorAP 918R | 1.4.11 |
| VigorAP 960 | 1.4.12 |
| VigorAP 1060 | 1.4.12 |
| VigorAP 906 | 1.4.13 |
| VigorAP 912 | 1.4.15 |
| VigorAP 903 | 1.4.22 |
Recognising Contribution
DrayTek would like to thank Jincheng Wang (@winmt), Professor Le Yu of Nanjing University of Posts and Telecommunications, and Professor Xiapu Luo of The Hong Kong Polytechnic University.
Contact Technical Support
If you have any security-related queries, please reach out to us via the contact form to connect with our technical team.
