目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2026-71932— DrayTek VigorSwitch 多个型号路径穿越漏洞

一分钟漏洞结论

影响对象
DrayTek Corporation VigorSwitch G2540xs
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

多个 DrayTek VigorSwitch 型号在 函数中存在目录遍历漏洞。该漏洞是由于对选项字段的验证不足所导致。远程攻击者可以通过构造包含路径遍历序列的恶意输入触发此漏洞,从而访问设备上的任意文件。但利用该漏洞需要拥有设备 Web 管理界面的有效管理员凭据。

CVSS 4.9 · Medium
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2026-71932 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
DrayTek VigorSwitch Multiple Models Path Traversal via getSyslogFile
来源: CVE Program / CVE List V5
Vulnerability Description
Multiple DrayTek VigorSwitch models contain a directory traversal vulnerability in the getSyslogFile function. The vulnerability is caused by insufficient validation of the option field. A remote attacker can trigger this vulnerability via crafted input containing path traversal sequences to access arbitrary files on the device. Exploitation requires valid administrative credentials for the device's web management interface.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
来源: CVE Program / CVE List V5
Vulnerability Type
对路径名的限制不恰当(路径遍历)
来源: CVE Program / CVE List V5

受影响产品

厂商 产品 影响版本 CPE 订阅
DrayTek Corporation VigorSwitch G2540xs 0 ~ 3.9.10 -
DrayTek Corporation VigorSwitch P2540xs 0 ~ 3.9.10 -
DrayTek Corporation VigorSwitch FX2120 0 ~ 3.9.10 -
DrayTek Corporation VigorSwitch G2282x 0 ~ 2.10.6 -
DrayTek Corporation VigorSwitch P2282x 0 ~ 2.10.6 -
DrayTek Corporation VigorSwitch Q2300x 0 ~ 2.10.7 -
DrayTek Corporation VigorSwitch PQ2300xb 0 ~ 2.10.7 -
DrayTek Corporation VigorSwitch G2542x 0 ~ 3.10.6 -
DrayTek Corporation VigorSwitch P2542x 0 ~ 3.10.6 -
DrayTek Corporation VigorSwitch P2542xh 0 ~ 3.10.6 -
DrayTek Corporation VigorSwitch PX2060 0 ~ 2.9.10 -
DrayTek Corporation VigorSwitch G1280 0 ~ 2.9.10 -
DrayTek Corporation VigorSwitch P1280 0 ~ 2.9.10 -
DrayTek Corporation VigorSwitch P1281x 0 ~ 2.9.10 -
DrayTek Corporation VigorSwitch G1282 0 ~ 2.9.10 -
DrayTek Corporation VigorSwitch P1282 0 ~ 2.9.10 -
DrayTek Corporation VigorSwitch G2121 0 ~ 2.9.10 -
DrayTek Corporation VigorSwitch P2121 0 ~ 2.9.10 -
DrayTek Corporation VigorSwitch PQ2121x 0 ~ 2.9.10 -
DrayTek Corporation VigorSwitch Q2121x 0 ~ 2.9.10 -
DrayTek Corporation VigorSwitch G2280x 0 ~ 2.9.10 -
DrayTek Corporation VigorSwitch P2280x 0 ~ 2.9.10 -
DrayTek Corporation VigorSwitch Q2200x 0 ~ 2.9.10 -
DrayTek Corporation VigorSwitch PQ2200xb 0 ~ 2.9.10 -
DrayTek Corporation VigorSwitch G2100 0 ~ 2.9.10 -
DrayTek Corporation VigorSwitch P2100 0 ~ 2.9.10 -
DrayTek Corporation VigorSwitch G2540x 0 ~ 2.9.10 -
DrayTek Corporation VigorSwitch P2540x 0 ~ 2.9.10 -

二、漏洞 CVE-2026-71932 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-71932 的情报信息

登录查看更多情报信息。

CVE-2026-71932 其他参考 (2)

同批安全公告 · DrayTek Corporation · 2026-08-24 · 共 40 条

CVE-2026-71914 9.8 CRITICAL DrayTek VigorAP 多款型号 dray_apm 预认证 OS 命令注入漏洞
CVE-2026-71921 9.8 CRITICAL DrayTek VigorSwitch 多个型号 setget.cgi 命令注入漏洞
CVE-2026-71933 9.1 CRITICAL DrayTek VigorSwitch 多型号 syslog 函数缺少授权漏洞
CVE-2026-71922 7.5 HIGH DrayTek VigorSwitch 多个型号通过 setget.cgi 的远程空指针解引用漏洞
CVE-2026-71934 7.2 HIGH DrayTek VigorSwitch多型号缓冲区溢出漏洞
CVE-2026-71905 7.2 HIGH DrayTek VigorAP多型号导出设置OS命令注入漏洞
CVE-2026-71919 7.2 HIGH DrayTek VigorSwitch 多个型号操作系统命令注入漏洞
CVE-2026-71910 7.2 HIGH DrayTek VigorAP 多个型号 OS 命令注入漏洞
CVE-2026-71906 7.2 HIGH DrayTek VigorAP 多个型号 setLan OS命令注入漏洞
CVE-2026-71912 7.2 HIGH DrayTek VigorAP 多个型号缓冲区溢出漏洞
CVE-2026-71917 7.2 HIGH DrayTek VigorSwitch 多个型号通过 pingtrace 命令注入漏洞
CVE-2026-71907 7.2 HIGH DrayTek VigorAP 多个型号OS命令注入漏洞
CVE-2026-71925 7.2 HIGH DrayTek VigorSwitch OS命令注入漏洞
CVE-2026-71915 7.2 HIGH DrayTek VigorSwitch 多个型号操作系统命令注入漏洞
CVE-2026-71923 7.2 HIGH DrayTek VigorSwitch 多个型号操作系统命令注入漏洞
CVE-2026-71935 7.2 HIGH DrayTek VigorSwitch 多型号 WebBackupAction 缓冲区溢出漏洞
CVE-2026-71941 7.2 HIGH DrayTek VigorSwitch 多款产品 diag_logmail 缓冲区溢出漏洞
CVE-2026-71938 7.2 HIGH DrayTek VigorSwitch多个型号缓冲区溢出漏洞
CVE-2026-71939 7.2 HIGH DrayTek VigorSwitch多个型号ACL设置缓冲区溢出漏洞
CVE-2026-71918 7.2 HIGH DrayTek VigorSwitch 多个型号 Web 备份命令注入漏洞

显示前 20 条,共 40 条。 查看全部 → →

IV. Related Vulnerabilities

V. Comments for CVE-2026-71932

暂无评论


发表评论