CVE-2026-71933: DrayTek VigorSwitch Multiple Models Missing Authorization in Syslog Functions
Multiple DrayTek VigorSwitch models contain unauthorized operation vulnerabilities in multiple syslog functions. The vulnerability is caused by missing authorization checks. A remote attacker can trigger these vulnerabilities via crafted requests to modify configuration, restart services, save startup configuration, or clear logs.
Affected Software
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The issue can be triggered remotely with crafted requests and does not require privileges or user interaction, as reflected by AV:N/AC:L/PR:N/UI:N.
What actions could an attacker perform through the affected functions?
An attacker may modify configuration, restart services, save the startup configuration, or clear logs through vulnerable syslog functions.
Is confidentiality impact reported for this vulnerability?
No confidentiality impact is reported. The supplied vector identifies integrity and availability impact as high, while confidentiality is none.