Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-71914: DrayTek VigorAP access points let attackers run commands
CVE-2026-71914 · published 10 days ago
Summary
Several DrayTek VigorAP Wi‑Fi devices can be tricked into running any code they want when they receive a specially crafted network message. An attacker from outside could gain full control of the device and the network it connects to. Install the latest firmware from DrayTek and block the device from untrusted networks until it is updated.
What to do
- Update draytek corporation vigorap 918r to version 1.4.11 or later.
- Update draytek corporation vigorap 960c to version 1.4.12 or later.
- Update draytek corporation vigorap 1060c to version 1.4.12 or later.
- Update draytek corporation vigorap 906 to version 1.4.13 or later.
- Update draytek corporation vigorap 912c to version 1.4.15 or later.
- Update draytek corporation vigorap 903 to version 1.4.22 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| draytek corporation | vigorap 918r | < 1.4.11 |
| draytek corporation | vigorap 960c | < 1.4.12 |
| draytek corporation | vigorap 1060c | < 1.4.12 |
| draytek corporation | vigorap 906 | < 1.4.13 |
| draytek corporation | vigorap 912c | < 1.4.15 |
| draytek corporation | vigorap 903 | < 1.4.22 |
Original advisory text
DrayTek VigorAP Multiple Models Pre-Authentication OS Command Injection via dray_apm
Multiple DrayTek VigorAP models contain a command injection vulnerability in the dray_apm component. The vulnerability is caused by insufficient validation of UDP message content after START_SPEED_TEST before command execution. A remote attacker can trigger this vulnerability via a crafted message to execute arbitrary commands with root privileges.
References
Severity
9.3
Critical
CVSS 3.1: 9.8 (MITRE)
Exploitation
EPSS 3%
Type
CWE-78OS Command Injection
Timeline
Published24 Aug 2026
Updated2 Sep 2026
First seen24 Aug 2026
Monitor software like this
Free during beta