Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-71918

CVE-2026-71918: DrayTek VigorSwitch RCE Vulnerability

CVE-2026-71918 is a command injection flaw in DrayTek VigorSwitch devices that allows authenticated attackers to execute arbitrary commands with root privileges. This post covers technical details, exploitation requirements, and mitigation strategies.

Published:

CVE-2026-71918 Overview

CVE-2026-71918 is a command injection vulnerability [CWE-78] affecting multiple DrayTek VigorSwitch models. The flaw resides in the webBackupAction function, which fails to sanitize the option, key, pw_encode, pathN, and valueN fields before passing them to system command execution. An authenticated remote attacker with administrative credentials can inject arbitrary operating system commands that execute with root privileges on the device. Successful exploitation grants full control over the affected switch, including the ability to modify configuration, pivot into internal networks, or persist across reboots.

Critical Impact

Authenticated attackers can execute arbitrary commands as root on affected DrayTek VigorSwitch devices, achieving full device compromise.

Affected Products

  • Multiple DrayTek VigorSwitch series models (see vendor advisory for model list)
  • Devices exposing the web management interface
  • Firmware versions prior to the August 2026 security release

Discovery Timeline

  • 2026-08-24 - CVE-2026-71918 published to NVD
  • 2026-08-26 - Last updated in NVD database

Technical Details for CVE-2026-71918

Vulnerability Analysis

The vulnerability originates in the webBackupAction handler exposed by the DrayTek VigorSwitch web management interface. This handler processes configuration backup requests and passes user-supplied parameters directly into system command invocations. Because the handler does not validate or escape shell metacharacters, an authenticated administrator can append arbitrary commands to the intended process invocation.

Exploitation yields code execution in the context of the switch's management daemon, which runs as root. From that position, attackers can extract credentials, alter port configuration, disable logging, or install persistent backdoors. On a network switch, this level of access enables traffic interception and lateral movement across VLAN boundaries.

Root Cause

The root cause is insufficient input filtering on five parameters accepted by webBackupAction: option, key, pw_encode, pathN, and valueN. These values are concatenated into shell command strings without argument-safe escaping or an allow-list of expected characters, satisfying the classic pattern of OS Command Injection described in CWE-78.

Attack Vector

The attack requires network reachability to the switch's web interface and valid administrative credentials. An attacker sends a crafted HTTP request to the backup endpoint with shell metacharacters embedded in one of the vulnerable fields. The web daemon then invokes the underlying shell command, executing the injected payload with root privileges. This is particularly impactful in environments where switch management interfaces are exposed beyond dedicated management VLANs or where administrator credentials have been reused or phished.

See the VulnCheck Advisory for DrayTek OS Command Injection for parameter-level technical details.

Detection Methods for CVE-2026-71918

Indicators of Compromise

  • HTTP POST requests to the switch backup endpoint containing shell metacharacters (;, |, `, $() in the option, key, pw_encode, pathN, or valueN fields
  • Unexpected outbound connections originating from the management IP of a VigorSwitch device
  • New or modified files in writable filesystem locations on the switch after a backup operation
  • Administrator login events from unusual source IP addresses immediately preceding backup requests

Detection Strategies

  • Inspect web-server and management logs on VigorSwitch devices for anomalous parameter values submitted to webBackupAction
  • Deploy network-based signatures that flag POST bodies to the backup endpoint containing shell metacharacters
  • Correlate administrative authentication events with configuration-backup activity to surface off-hours or scripted access

Monitoring Recommendations

  • Forward switch syslog and web-interface access logs to a centralized SIEM for retention and correlation
  • Alert on any successful administrative login to network infrastructure from outside the management subnet
  • Baseline normal backup activity by frequency and source, then alert on deviations

How to Mitigate CVE-2026-71918

Immediate Actions Required

  • Apply the firmware update referenced in the DrayTek Security Advisory August 2026 to every affected VigorSwitch model
  • Restrict access to the web management interface to a dedicated management VLAN or jump host
  • Rotate administrative credentials on all VigorSwitch devices, particularly where credentials may have been reused
  • Audit recent configuration and firmware for unauthorized changes

Patch Information

DrayTek released fixed firmware in the August 2026 VigorSwitch security advisory. Administrators should consult the vendor advisory to identify the exact fixed firmware version for their model and upgrade accordingly. Confirm the upgrade by verifying the firmware banner and re-running configuration audits after reboot.

Workarounds

  • Disable the web management interface on untrusted network segments and manage devices exclusively via out-of-band or console access until patched
  • Enforce firewall rules that permit management HTTP/HTTPS access only from named administrator workstations
  • Require multi-factor authentication for the jump hosts used to reach switch management interfaces
  • Monitor administrative sessions for command-injection payload patterns and terminate suspicious sessions

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.