Advisories

DrayTek VigorSwitch Multiple Models OS Command Injection via getVid

Go Back
severity
high
date
Affecting
  • VigorSwitch G2540xs >= 0, < 3.9.10

  • VigorSwitch P2540xs >= 0, < 3.9.10

  • VigorSwitch FX2120 >= 0, < 3.9.10

  • VigorSwitch G2282x >= 0, < 2.10.6

  • VigorSwitch P2282x >= 0, < 2.10.6

  • VigorSwitch Q2300x >= 0, < 2.10.7

  • VigorSwitch PQ2300xb >= 0, < 2.10.7

  • VigorSwitch G2542x >= 0, < 3.10.6

  • VigorSwitch P2542x >= 0, < 3.10.6

  • VigorSwitch P2542xh >= 0, < 3.10.6

  • VigorSwitch PX2060 >= 0, < 2.9.10

  • VigorSwitch G1280 >= 0, < 2.9.10

  • VigorSwitch P1280 >= 0, < 2.9.10

  • VigorSwitch P1281x >= 0, < 2.9.10

  • VigorSwitch G1282 >= 0, < 2.9.10

  • VigorSwitch P1282 >= 0, < 2.9.10

  • VigorSwitch G2121 >= 0, < 2.9.10

  • VigorSwitch P2121 >= 0, < 2.9.10

  • VigorSwitch PQ2121x >= 0, < 2.9.10

  • VigorSwitch Q2121x >= 0, < 2.9.10

  • VigorSwitch G2280x >= 0, < 2.9.10

  • VigorSwitch P2280x >= 0, < 2.9.10

  • VigorSwitch Q2200x >= 0, < 2.9.10

  • VigorSwitch PQ2200xb >= 0, < 2.9.10

  • VigorSwitch G2100 >= 0, < 2.9.10

  • VigorSwitch P2100 >= 0, < 2.9.10

  • VigorSwitch G2540x >= 0, < 2.9.10

  • VigorSwitch P2540x >= 0, < 2.9.10

CWE
  • CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVSS
8.6
CVSS V4 Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Credit
Jincheng Wang (@winmt), Le Yu (Nanjing University of Posts and Telecommunications), Xiapu Luo (The Hong Kong Polytechnic University)
Description
Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the getVid function. The vulnerability is caused by insufficient filtering of the username and password fields before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administrative credentials for the device's web management interface.

Ready to get Started?

Explore VulnCheck, a next-generation Cyber Threat Intelligence platform, which provides exploit and vulnerability intelligence to help you prioritize and remediate vulnerabilities that matter.
  • Vulnerability Prioritization
    Prioritize vulnerabilities that matter based on the threat landscape and defer vulnerabilities that don't.
  • Early Warning System
    Real-time alerting of changes in the vulnerability landscape so that you can take action before the attacks start.