CVE-2026-71926 | DrayTek VigorSwitch Command Execution setDevice username/password/location command injection

SecurityVulns

A vulnerability described as very critical has been identified in DrayTek VigorSwitch. Affected is the function setDevice of the component Command Execution. Executing a manipulation of the argument username/password/location can lead to command injection.

This vulnerability is handled as CVE-2026-71926. The attack can be executed remotely. There is not any exploit available.VulDB Recent EntriesRead More