NCSC | Security Advisories
Bekijk RSS-feed

Security Advisories

Download

Security Advisory; NCSC-2026-0328 [1.0.0]

Security Advisory
NCSC-2026-0328 [1.0.0]
Publicatie
26-08-2026 11:03 (Europe/Amsterdam)
Prioriteit
Normaal
Betreft
Kwetsbaarheden verholpen in DrayTek VigorSwitch

Kenmerken

  • Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
  • Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
  • Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
  • NULL Pointer Dereference
  • Missing Authorization

Omschrijving

DrayTek heeft meerdere kwetsbaarheden verholpen in de VigorSwitch productlijn.

De kwetsbaarheden betreffen voornamelijk command injection, buffer overflow, null pointer dereference, directory traversal en onvoldoende autorisatiecontroles in diverse functies van de DrayTek VigorSwitch apparaten. Command injection kwetsbaarheden bevinden zich onder andere in functies zoals jsonstatus, commandTable, pingtrace, webBackupAction, sysreboot, auth_set, getVid, getDetail, setDevice, rebDevice, fdftDevice, setDevProto, setTime, tftp_upgrade en setDevNet. Deze maken het mogelijk voor een aanvaller om willekeurige commando's met root privileges uit te voeren. Sommige command injection kwetsbaarheden zijn pre-authenticatie, zoals in de setget.cgi interface, waardoor geen voorafgaande authenticatie vereist is voor exploitatie.

Buffer overflow kwetsbaarheden zijn aanwezig in functies zoals pingtrace, webBackupAction, sysreboot, poe_schedule_profile, switch_lan_gvrp, acl_general_setup Add ACE en Edit ACE, diag_logmail en mail_mailalert. Deze kunnen leiden tot denial of service of uitvoering van willekeurige code onder administratieve rechten.

Null pointer dereference kwetsbaarheden in formlogout en setget.cgi kunnen leiden tot een denial of service door het crashen van de service.

Directory traversal in getSyslogFile maakt het mogelijk om, mits geauthenticeerd, toegang te krijgen tot willekeurige bestanden op het systeem. Onvoldoende autorisatiecontroles in syslog functies stellen een aanvaller in staat om configuraties te wijzigen, services te herstarten, configuraties op te slaan of logs te wissen zonder de juiste rechten.

Exploitatie van deze kwetsbaarheden vereist in de meeste gevallen geldige administratieve credentials, behalve bij de pre-authenticatie command injection en null pointer dereference in setget.cgi.

Oplossingen

DrayTek heeft updates uitgebracht om de kwetsbaarheden in de VigorSwitch productlijn te verhelpen. Zie bijgevoegde referenties voor meer informatie.

Referenties

CVE's

Producten

DrayTek
Vigor
DrayTek Corporation
VigorSwitch FX2120
VigorSwitch G1280
VigorSwitch G1282
VigorSwitch G2100
VigorSwitch G2121
VigorSwitch G2280x
VigorSwitch G2282x
VigorSwitch G2540x
VigorSwitch G2540xs
VigorSwitch G2542x
VigorSwitch P1280
VigorSwitch P1281x
VigorSwitch P1282
VigorSwitch P2100
VigorSwitch P2121
VigorSwitch P2280x
VigorSwitch P2282x
VigorSwitch P2540x
VigorSwitch P2540xs
VigorSwitch P2542x
VigorSwitch P2542xh
VigorSwitch PQ2121x
VigorSwitch PQ2200xb
VigorSwitch PQ2300xb
VigorSwitch PX2060
VigorSwitch Q2121x
VigorSwitch Q2200x
VigorSwitch Q2300x

Disclaimer

The Netherlands Cyber Security Center (henceforth: NCSC-NL) maintains this page to enhance access to its information and security advisories. The use of this security advisory is subject to the following terms and conditions: NCSC-NL makes every reasonable effort to ensure that the content of this page is kept up to date, and that it is accurate and complete. Nevertheless, NCSC-NL cannot entirely rule out the possibility of errors, and therefore cannot give any warranty in respect of its completeness, accuracy or continuous keeping up-to-date. The information contained in this security advisory is intended solely for the purpose of providing general information to professional users. No rights can be derived from the information provided therein. NCSC-NL and the Kingdom of the Netherlands assume no legal liability or responsibility for any damage resulting from either the use or inability of use of this security advisory. This includes damage resulting from the inaccuracy of incompleteness of the information contained in the advisory. This security advisory is subject to Dutch law. All disputes related to or arising from the use of this advisory will be submitted to the competent court in The Hague. This choice of means also applies to the court in summary proceedings.