← volver
CVE-2026-71921criticalCWE-78

DrayTek VigorSwitch Multiple Models Pre-Authentication OS Command Injection via setget.cgi

28Vexday Risk Score

Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.

ssvc Trackcvss 9.3epss 3.2%
probabilidad de explotación
3.2%top 12% de las CVE
explotación observada
noninguna fuente lo reporta
Multiple DrayTek VigorSwitch models contain a pre-authentication command injection vulnerability in the setget.cgi interface. The vulnerability is caused by insufficient filtering of the pass field before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N