CVE-2026-71934: DrayTek VigorSwitch Multiple Models Buffer Overflow via pingtrace
Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the pingtrace function. The vulnerability is caused by missing length checks when the host, count, and interval fields are concatenated into a fixed-size buffer. A remote attacker can trigger this vulnerability via crafted input, causing a denial of service or potentially executing arbitrary commands. Exploitation requires valid administrative credentials for the device's web management interface.
Affected Software
Event History
Frequently Asked Questions
Can an unauthenticated remote attacker exploit this issue?
No. Exploitation requires valid administrative credentials for the device's web management interface.
What access and inputs are needed to trigger the vulnerability?
An attacker must access the web management interface with administrative credentials and submit crafted values to the pingtrace host, count, or interval fields.
What could successful exploitation allow?
Successful exploitation can cause a denial of service and may potentially allow arbitrary command execution on the affected device.