CVE-2026-71937 | DrayTek VigorSwitch PX2060 poe_schedule_profile buffer overflow

SecurityVulns

A vulnerability marked as very critical has been reported in DrayTek VigorSwitch G1280, VigorSwitch G1282, VigorSwitch G2100, VigorSwitch G2121, VigorSwitch G2280x, VigorSwitch G2282x, VigorSwitch G2540x, VigorSwitch G2540xs, VigorSwitch G2542x, VigorSwitch P1280, VigorSwitch P1281x, VigorSwitch P1282, VigorSwitch P2100, VigorSwitch P2121, VigorSwitch P2280x, VigorSwitch P2282x, VigorSwitch P2540x, VigorSwitch P2540xs, VigorSwitch P2542x, VigorSwitch P2542xh, VigorSwitch PQ2121x, VigorSwitch PQ2200xb, VigorSwitch PQ2300xb, VigorSwitch Q2121x, VigorSwitch Q2200x, VigorSwitch Q2300x and VigorSwitch PX2060. Affected by this issue is the function poe_schedule_profile. The manipulation of the argument start_date/start_time/duration_time/how_often/weekdays/monthly_date/cycle_duration leads to buffer overflow.

This vulnerability is traded as CVE-2026-71937. It is possible to initiate the attack remotely. There is no exploit available.VulDB Recent EntriesRead More