CVE-2026-71919 | DrayTek VigorSwitch G2540xs Web Management Interface sysreboot config/act/pathN/valueN command injection

SecurityVulns

A vulnerability was found in DrayTek VigorSwitch G2540xs, VigorSwitch P2540xs, VigorSwitch FX2120, VigorSwitch G2282x, VigorSwitch P2282x, VigorSwitch Q2300x, VigorSwitch PQ2300xb, VigorSwitch G2542x, VigorSwitch P2542x, VigorSwitch P2542xh, VigorSwitch PX2060, VigorSwitch G1280, VigorSwitch P1280, VigorSwitch P1281x, VigorSwitch G1282, VigorSwitch P1282, VigorSwitch G2121, VigorSwitch P2121, VigorSwitch PQ2121x, VigorSwitch Q2121x, VigorSwitch G2280x, VigorSwitch P2280x, VigorSwitch Q2200x, VigorSwitch PQ2200xb, VigorSwitch G2100, VigorSwitch P2100, VigorSwitch G2540x and VigorSwitch P2540x. It has been classified as very critical. This vulnerability affects the function sysreboot of the component Web Management Interface. Performing a manipulation of the argument config/act/pathN/valueN results in command injection.

This vulnerability is cataloged as CVE-2026-71919. It is possible to initiate the attack remotely. There is no exploit available.VulDB Recent EntriesRead More