CVE-2026-71912
Received Received - Intake

Buffer Overflow in DrayTek VigorAP via CMD6 Field

Vulnerability report for CVE-2026-71912, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-24

Last updated on: 2026-08-24

Assigner: VulnCheck

Description

Multiple DrayTek VigorAP models contain a buffer overflow vulnerability in the apautotest function. The vulnerability is caused by missing length checks during memory copy operations involving the CMD6 field. A remote attacker can trigger this vulnerability via crafted input, causing a denial of service or potentially executing arbitrary commands. Exploitation requires valid administrative credentials for the device's web management interface.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-24
Last Modified
2026-08-24
Generated
2026-08-24
AI Q&A
2026-08-24
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 11 associated CPEs
Vendor Product Version / Range
draytek vigorap 1.4.11
draytek vigorap 1.4.12
draytek vigorap 1.4.13
draytek vigorap 1.4.15
draytek vigorap 1.4.22
draytek vigorap *
draytek vigorap to 1.4.11 (exc)
draytek vigorap to 1.4.12 (exc)
draytek vigorap to 1.4.13 (exc)
draytek vigorap to 1.4.15 (exc)
draytek vigorap to 1.4.22 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-120 The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-71912 is a buffer overflow vulnerability in multiple DrayTek VigorAP models. It occurs in the apautotest function due to missing length checks during memory copy operations involving the CMD6 field. A remote attacker with valid admin credentials can exploit this to cause denial of service or execute arbitrary commands.

Detection Guidance

Detecting this vulnerability requires checking if your DrayTek VigorAP device models and firmware versions are affected. Verify the model and version against the list: VigorAP 918R (below 1.4.11), VigorAP 960C (below 1.4.12), VigorAP 1060C (below 1.4.12), VigorAP 906 (below 1.4.13), VigorAP 912C (below 1.4.15), VigorAP 903 (below 1.4.22).

Commands to check firmware version vary by model. Typically, log in to the device's web management interface and navigate to the system or firmware section. Alternatively, use SSH or Telnet to run commands like 'show version' or 'cat /etc/version' if supported.

Impact Analysis

This vulnerability allows attackers to crash devices or run malicious code remotely. It requires admin access but could lead to network disruption, unauthorized access, or further compromise of connected systems if exploited.

Compliance Impact

This vulnerability could impact compliance with GDPR and HIPAA by enabling unauthorized access to network devices. Exploitation may lead to data breaches, unauthorized command execution, or service disruption, violating confidentiality and integrity requirements in these regulations.

Mitigation Strategies

Immediately update affected DrayTek VigorAP devices to the latest firmware versions specified in the vendor advisory. Ensure no unauthorized administrative access exists by reviewing user accounts and credentials.

Restrict access to the device's web management interface by limiting allowed IP addresses or enabling firewall rules. Monitor network traffic for unusual activity related to the apautotest function.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-71912. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart