CVE-2026-71913
Received Received - Intake

Command Injection in DrayTek VigorAP

Vulnerability report for CVE-2026-71913, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-24

Last updated on: 2026-08-24

Assigner: VulnCheck

Description

Multiple DrayTek VigorAP models contain a command injection vulnerability in the upload_settings.cgi interface. The vulnerability is caused by insufficient filtering before the restorekey field is concatenated into a shell command. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administrative credentials for the device's web management interface.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-24
Last Modified
2026-08-24
Generated
2026-08-24
AI Q&A
2026-08-24
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 7 associated CPEs
Vendor Product Version / Range
draytek vigorap *
draytek vigorap_918r to 1.4.11 (exc)
draytek vigorap_960c to 1.4.12 (exc)
draytek vigorap_1060c to 1.4.12 (exc)
draytek vigorap_906 to 1.4.13 (exc)
draytek vigorap_912c to 1.4.15 (exc)
draytek vigorap_903 to 1.4.22 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-78 The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Multiple DrayTek VigorAP models have a command injection vulnerability in the upload_settings.cgi interface. The issue occurs because the restorekey field is not properly filtered before being used in a shell command. An attacker with valid admin credentials for the web management interface can exploit this to execute arbitrary commands with root privileges.

Detection Guidance

Detection requires checking for vulnerable DrayTek VigorAP models and their firmware versions. Verify if any of the affected models (VigorAP 918R, 960C, 1060C, 906, 912C, 903) are running firmware versions below the specified thresholds (e.g., VigorAP 918R < 1.4.11).

Impact Analysis

An attacker could gain full control over affected DrayTek VigorAP devices, allowing them to manipulate network traffic, steal sensitive data, or use the device as a foothold for further attacks within the network.

Compliance Impact

This vulnerability could lead to unauthorized access and data breaches, violating confidentiality requirements in GDPR and HIPAA. Organizations may face fines or penalties for failing to protect sensitive data due to unpatched devices.

Mitigation Strategies

Immediately update DrayTek VigorAP devices to the latest firmware version to patch the command injection vulnerability in the upload_settings.cgi interface. Ensure administrative credentials for the web management interface are strong and not shared. Monitor network traffic for unusual activity from these devices.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-71913. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart