CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

NCSC-2026-0328 [1.00] [M/H] Kwetsbaarheden verholpen in DrayTek VigorSwitch

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 6029

As cited

Copy frozen at (site build).

NCSC-2026-0328 [1.00] [M/H] Kwetsbaarheden verholpen in DrayTek VigorSwitch

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

NCSC-2026-0328 [1.00] [M/H] Kwetsbaarheden verholpen in DrayTek VigorSwitch

DrayTek has patched multiple vulnerabilities in VigorSwitch devices, including command injection, buffer overflow, null pointer dereference, directory traversal, and insufficient authorization checks across various functions. Several command injection flaws in interfaces like setget.cgi are pre-authentication, allowing unauthenticated remote code execution (RCE) with root privileges. Buffer overflow vulnerabilities may lead to denial of service or arbitrary code execution under administrative rights.

Why it matters: Network administrators running DrayTek VigorSwitch devices must apply patches immediately, particularly for pre-authentication RCE flaws that expose devices to unauthenticated remote attacks without requiring valid credentials.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary