CVE-2026-71905: DrayTek VigorAP Multiple Models OS Command Injection via ExportSettings
Multiple DrayTek VigorAP models contain a command injection vulnerability in the ExportSettings function. The vulnerability is caused by insufficient filtering of the backupkey, backuptype, and realtime fields before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administrative credentials for the device's web management interface.
Other sources
Volmarg Personal Management System contains a path traversal vulnerability that allows authenticated attackers to read arbitrary files by supplying absolute filesystem paths to the GET /public/get-file/{path} endpoint. The path route parameter is passed directly to filegetcontents() without canonicalization against a permitted base directory, enabling attackers to retrieve sensitive files accessible to the PHP-FPM worker process without using directory traversal sequences.
— NVD
Affected Software
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The attacker needs valid administrative credentials for the device's web management interface. They can then submit crafted values through the ExportSettings function.
What impact can successful exploitation have?
Successful exploitation allows execution of arbitrary operating system commands with root privileges on the affected device. This can compromise confidentiality, integrity, and availability.
Which inputs are involved in the vulnerable functionality?
The affected ExportSettings function insufficiently filters the backupkey, backuptype, and realtime fields before command execution.