As cited
Copy frozen at (site build).
NCSC-2026-0328 [1.00] [M/H] Kwetsbaarheden verholpen in DrayTek VigorSwitch
No summary had been written when this copy was frozen.
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
NCSC-2026-0328 [1.00] [M/H] Kwetsbaarheden verholpen in DrayTek VigorSwitch
DrayTek has patched multiple vulnerabilities in VigorSwitch devices, including command injection, buffer overflow, null pointer dereference, directory traversal, and insufficient authorization checks across various functions. Several command injection flaws in interfaces like setget.cgi are pre-authentication, allowing unauthenticated remote code execution (RCE) with root privileges. Buffer overflow vulnerabilities may lead to denial of service or arbitrary code execution under administrative rights.
Why it matters: Network administrators running DrayTek VigorSwitch devices must apply patches immediately, particularly for pre-authentication RCE flaws that expose devices to unauthenticated remote attacks without requiring valid credentials.
- Source published
- First seen by Cybersecurity Tracker