CVE-2026-71922: DrayTek VigorSwitch Multiple Models Pre-Authentication NULL Pointer Dereference via setget.cgi
Published Aug 24, 2026
·Updated
Multiple DrayTek VigorSwitch models contain a pre-authentication null pointer dereference vulnerability in the setget.cgi interface. The vulnerability is caused by missing validation when the pass field is absent. A remote attacker can trigger this vulnerability via a crafted request to crash the service and cause a denial of service.
Affected Software
1 affected component
DrayTek VigorSwitch=
Event History
Aug 24, 2026
CVE Published
via MITRE·05:07 PM
Data Sourced
via MITRE·05:07 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What must an attacker have to exploit this issue?
An attacker needs network access to the affected device's setget.cgi interface and can use a crafted request. Authentication and user interaction are not required.
2
Does successful exploitation expose or alter device data?
The available severity data indicates no confidentiality or integrity impact. The documented impact is an availability loss caused by crashing the affected service.