Multiple Vulnerabilities in VigorSwitch Series
Number: DSA-2026-003
On June 1, several potential security vulnerabilities were identified within the DrayTek VigorSwitch mainfunction.cgi component, including Command Injection, Null Pointer Dereference, Directory Traversal and Buffer Overflow.
Several vulnerabilities have been identified in the affected code. At the time of publication, DrayTek is not aware of any successful exploitation methods or active attacks targeting these vulnerabilities. If a viable exploitation method were identified, it would likely require an attacker to possess valid administrative credentials and be able to authenticate to the switch's web management interface.
Should a method be identified that allows these conditions to be reached and successfully exploited, they could potentially result in arbitrary code execution on an affected appliance. However, the feasibility of such exploitation has not been demonstrated. DrayTek Corp has addressed these findings in updated firmware releases and recommends that customers upgrade to the versions listed below as a preventive security measure.
Vulnerability Details
| CVE Number | Description |
|---|---|
| CVE-2026-71915 | Command Injection |
| CVE-2026-71916 | Command Injection |
| CVE-2026-71917 | Command Injection |
| CVE-2026-71918 | Command Injection |
| CVE-2026-71919 | Command Injection |
| CVE-2026-71920 | Null Pointer Dereference |
| CVE-2026-71921 | Command Injection |
| CVE-2026-71922 | Null Pointer Dereference |
| CVE-2026-71923 | Command Injection |
| CVE-2026-71924 | Command Injection |
| CVE-2026-71925 | Command Injection |
| CVE-2026-71926 | Command Injection |
| CVE-2026-71927 | Command Injection |
| CVE-2026-71928 | Command Injection |
| CVE-2026-71929 | Command Injection |
| CVE-2026-71930 | Command Injection |
| CVE-2026-71931 | Command Injection |
| CVE-2026-71932 | Directory Traversal |
| CVE-2026-71933 | Unauthorized Operation (Missing Authorization) |
| CVE-2026-71934 | Buffer Overflow |
| CVE-2026-71935 | Buffer Overflow |
| CVE-2026-71936 | Buffer Overflow |
| CVE-2026-71937 | Buffer Overflow |
| CVE-2026-71938 | Buffer Overflow |
| CVE-2026-71939 | Buffer Overflow |
| CVE-2026-71940 | Buffer Overflow |
| CVE-2026-71941 | Buffer Overflow |
| CVE-2026-71942 | Buffer Overflow |
| CVE-2026-71943 | Command Injection |
The firmware updates are released for the following models. No other models are affected. Please click here to download and upgrade the firmware for your specific model as soon as possible to ensure your system remains up to date.
Affected Products and Recommended Firmware Versions
| Model | Fixed Firmware Version |
|---|---|
| VigorSwitch G2540xs / P2540xs | 3.9.10 |
| VigorSwitch FX2120 | 3.9.10 |
| VigorSwitch C??8x / P??8x | 2.10.6 |
| VigorSwitch G2300x / PQ2300xb | 2.10.7 |
| VigorSwitch C254x / P2542x / P2542xh | 3.10.6 |
| VigorSwitch PX2060 | 2.9.10 |
| VigorSwitch G1280 / P1280 | 2.9.10 |
| VigorSwitch P1281x | 2.9.10 |
| VigorSwitch G1282 / P1282 | 2.9.10 |
| VigorSwitch Q2121 / P2121 | 2.9.10 |
| VigorSwitch PQ212x / Q212x | 2.9.10 |
| VigorSwitch Q2280x / P2280x | 2.9.10 |
| VigorSwitch Q2200x / PQ2200xb | 2.9.10 |
| VigorSwitch G2100 / P2100 | 2.9.10 |
| VigorSwitch G2540x / P2540x | 2.9.10 |
Recognising Contribution
DrayTek would like to thank Jincheng Wang (@winmt), Professor Le Yu of Nanjing University of Posts and Telecommunications, and Professor Xiapu Luo of The Hong Kong Polytechnic University.
Contact Technical Support
If you have any security-related queries, please reach out to us via the contact form to connect with our technical team.
