CVE-2026-71905

Summary

Multiple DrayTek VigorAP models contain a command injection vulnerability in the ExportSettings function. The vulnerability is caused by insufficient filtering of the backupkey, backuptype, and realtime fields before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administrative credentials for the device's web management interface.

Affected Software

VendorProductVersion RangeStatus
DrayTek CorporationVigorAP 918R0 < 1.4.11affected
DrayTek CorporationVigorAP 960C0 < 1.4.12affected
DrayTek CorporationVigorAP 1060C0 < 1.4.12affected
DrayTek CorporationVigorAP 9060 < 1.4.13affected
DrayTek CorporationVigorAP 912C0 < 1.4.15affected
DrayTek CorporationVigorAP 9030 < 1.4.22affected

Weaknesses

  • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References