Multiple Vulnerabilities in VigorSwitch Series

Number: DSA-2026-003

On June 1, several potential security vulnerabilities were identified within the DrayTek VigorSwitch mainfunction.cgi component, including Command Injection, Null Pointer Dereference, Directory Traversal and Buffer Overflow.

Several vulnerabilities have been identified in the affected code. At the time of publication, DrayTek is not aware of any successful exploitation methods or active attacks targeting these vulnerabilities. If a viable exploitation method were identified, it would likely require an attacker to possess valid administrative credentials and be able to authenticate to the switch's web management interface.

Should a method be identified that allows these conditions to be reached and successfully exploited, they could potentially result in arbitrary code execution on an affected appliance. However, the feasibility of such exploitation has not been demonstrated. DrayTek Corp has addressed these findings in updated firmware releases and recommends that customers upgrade to the versions listed below as a preventive security measure.

Vulnerability Details

CVE NumberDescription
CVE-2026-71915 Command Injection
CVE-2026-71916 Command Injection
CVE-2026-71917 Command Injection
CVE-2026-71918 Command Injection
CVE-2026-71919 Command Injection
CVE-2026-71920 Null Pointer Dereference
CVE-2026-71921 Command Injection
CVE-2026-71922 Null Pointer Dereference
CVE-2026-71923 Command Injection
CVE-2026-71924 Command Injection
CVE-2026-71925 Command Injection
CVE-2026-71926 Command Injection
CVE-2026-71927 Command Injection
CVE-2026-71928 Command Injection
CVE-2026-71929 Command Injection
CVE-2026-71930 Command Injection
CVE-2026-71931 Command Injection
CVE-2026-71932 Directory Traversal
CVE-2026-71933 Unauthorized Operation (Missing Authorization)
CVE-2026-71934 Buffer Overflow
CVE-2026-71935 Buffer Overflow
CVE-2026-71936 Buffer Overflow
CVE-2026-71937 Buffer Overflow
CVE-2026-71938 Buffer Overflow
CVE-2026-71939 Buffer Overflow
CVE-2026-71940 Buffer Overflow
CVE-2026-71941 Buffer Overflow
CVE-2026-71942 Buffer Overflow
CVE-2026-71943 Command Injection

The firmware updates are released for the following models. No other models are affected. Please click here to download and upgrade the firmware for your specific model as soon as possible to ensure your system remains up to date.

Affected Products and Recommended Firmware Versions

ModelFixed Firmware Version
VigorSwitch G2540xs / P2540xs 3.9.10
VigorSwitch FX2120 3.9.10
VigorSwitch C??8x / P??8x 2.10.6
VigorSwitch G2300x / PQ2300xb 2.10.7
VigorSwitch C254x / P2542x / P2542xh 3.10.6
VigorSwitch PX2060 2.9.10
VigorSwitch G1280 / P1280 2.9.10
VigorSwitch P1281x 2.9.10
VigorSwitch G1282 / P1282 2.9.10
VigorSwitch Q2121 / P2121 2.9.10
VigorSwitch PQ212x / Q212x 2.9.10
VigorSwitch Q2280x / P2280x 2.9.10
VigorSwitch Q2200x / PQ2200xb 2.9.10
VigorSwitch G2100 / P2100 2.9.10
VigorSwitch G2540x / P2540x 2.9.10

Recognising Contribution

DrayTek would like to thank Jincheng Wang (@winmt), Professor Le Yu of Nanjing University of Posts and Telecommunications, and Professor Xiapu Luo of The Hong Kong Polytechnic University.

Contact Technical Support

If you have any security-related queries, please reach out to us via the contact form to connect with our technical team.