Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

VigorSwitch G2540xs — Vulnerabilities & Security Advisories 29

All 29 CVE vulnerabilities found in VigorSwitch G2540xs, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known security weaknesses associated with the VigorSwitch G2540xs switch from DrayTek, categorized under common vulnerability types. It collects a comprehensive list of reported issues affecting this specific network hardware model, spanning from its initial release through the most recent documented updates. The data includes various severity levels, covering buffer overflows, configuration issues, and other exploitable flaws that have been identified by security researchers and official vendor disclosures. Here, you can track DrayTek’s advisory history to understand how they respond to emerging threats. You can also analyze specific weakness classes to see how they manifest in managed Ethernet switches, helping administrators prioritize patching efforts. Additionally, the page allows users to look up the VigorSwitch G2540xs’s vulnerability history, providing a clear timeline of when each issue was discovered and addressed. This information is vital for security professionals tasked with maintaining the integrity of network infrastructure. By reviewing these entries, IT teams can better assess their exposure to known risks and implement appropriate mitigations. The aggregation serves as a central reference point for understanding the security posture of this device over time, ensuring that users remain informed about critical updates and potential exploits. This resource supports proactive security management by consolidating disparate reports into a single, accessible view, facilitating informed decision-making regarding firmware updates and network security policies.

Vendor: DrayTek Corporation

CVE ID Title CVSS Severity Published
CVE-2026-71943 DrayTek VigorSwitch Multiple Models OS Command Injection via setDevNet CWE-78 7.2 High 2026-08-24
CVE-2026-71942 DrayTek VigorSwitch Multiple Models Buffer Overflow via mail_mailalert CWE-120 7.2 High 2026-08-24
CVE-2026-71941 DrayTek VigorSwitch Multiple Models Buffer Overflow via diag_logmail CWE-120 7.2 High 2026-08-24
CVE-2026-71940 DrayTek VigorSwitch Multiple Models Buffer Overflow via acl_general_setup Edit ACE CWE-120 7.2 High 2026-08-24
CVE-2026-71939 DrayTek VigorSwitch Multiple Models Buffer Overflow via acl_general_setup Add ACE CWE-120 7.2 High 2026-08-24
CVE-2026-71938 DrayTek VigorSwitch Multiple Models Buffer Overflow via switch_lan_gvrp CWE-120 7.2 High 2026-08-24
CVE-2026-71937 DrayTek VigorSwitch Multiple Models Buffer Overflow via poe_schedule_profile CWE-120 7.2 High 2026-08-24
CVE-2026-71936 DrayTek VigorSwitch Multiple Models Buffer Overflow via sysreboot CWE-120 7.2 High 2026-08-24
CVE-2026-71934 DrayTek VigorSwitch Multiple Models Buffer Overflow via pingtrace CWE-120 7.2 High 2026-08-24
CVE-2026-71935 DrayTek VigorSwitch Multiple Models Buffer Overflow via webBackupAction CWE-120 7.2 High 2026-08-24
CVE-2026-71933 DrayTek VigorSwitch Multiple Models Missing Authorization in Syslog Functions CWE-862 9.1 Critical 2026-08-24
CVE-2026-71931 DrayTek VigorSwitch Multiple Models OS Command Injection via tftp_upgrade CWE-78 7.2 High 2026-08-24
CVE-2026-71932 DrayTek VigorSwitch Multiple Models Path Traversal via getSyslogFile CWE-22 4.9 Medium 2026-08-24
CVE-2026-71930 DrayTek VigorSwitch Multiple Models OS Command Injection via setTime CWE-78 7.2 High 2026-08-24
CVE-2026-71928 DrayTek VigorSwitch Multiple Models OS Command Injection via fdftDevice CWE-78 7.2 High 2026-08-24
CVE-2026-71929 DrayTek VigorSwitch Multiple Models OS Command Injection via setDevProto CWE-78 7.2 High 2026-08-24
CVE-2026-71927 DrayTek VigorSwitch Multiple Models OS Command Injection via rebDevice CWE-78 7.2 High 2026-08-24
CVE-2026-71925 DrayTek VigorSwitch Multiple Models OS Command Injection via getDetail CWE-78 7.2 High 2026-08-24
CVE-2026-71926 DrayTek VigorSwitch Multiple Models OS Command Injection via setDevice CWE-78 7.2 High 2026-08-24
CVE-2026-71924 DrayTek VigorSwitch Multiple Models OS Command Injection via getVid CWE-78 7.2 High 2026-08-24
CVE-2026-71922 DrayTek VigorSwitch Multiple Models Pre-Authentication NULL Pointer Dereference via setget.cgi CWE-476 7.5 High 2026-08-24
CVE-2026-71923 DrayTek VigorSwitch Multiple Models OS Command Injection via auth_set CWE-78 7.2 High 2026-08-24
CVE-2026-71921 DrayTek VigorSwitch Multiple Models Pre-Authentication OS Command Injection via setget.cgi CWE-78 9.8 Critical 2026-08-24
CVE-2026-71919 DrayTek VigorSwitch Multiple Models OS Command Injection via sysreboot CWE-78 7.2 High 2026-08-24
CVE-2026-71920 DrayTek VigorSwitch Multiple Models NULL Pointer Dereference via formlogout CWE-476 4.9 Medium 2026-08-24
CVE-2026-71918 DrayTek VigorSwitch Multiple Models OS Command Injection via webBackupAction CWE-78 7.2 High 2026-08-24
CVE-2026-71917 DrayTek VigorSwitch Multiple Models OS Command Injection via pingtrace CWE-78 7.2 High 2026-08-24
CVE-2026-71916 DrayTek VigorSwitch Multiple Models OS Command Injection via commandTable CWE-78 7.2 High 2026-08-24
CVE-2026-71915 DrayTek VigorSwitch Multiple Models OS Command Injection via jsonstatus CWE-78 7.2 High 2026-08-24

All 29 known CVE vulnerabilities affecting VigorSwitch G2540xs with full Chinese analysis, references, and POCs where available.