Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

DrayTek Corporation — Vulnerabilities & Security Advisories 40

Browse all 40 CVE security advisories affecting DrayTek Corporation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

This page is a comprehensive vulnerability aggregation index for DrayTek Corporation, focusing on network security appliances and routing equipment. It compiles known weaknesses across various DrayTek product lines, capturing security flaws ranging from remote code execution and privilege escalation to cross-site scripting and buffer overflow issues. The dataset covers vulnerabilities reported and patched over the last several years, ensuring a historical perspective on the vendor's security posture and response timelines. Readers can use this resource to track DrayTek’s security advisories as they are issued, providing insight into how quickly the vendor addresses critical issues in their hardware and firmware. Additionally, this page allows users to understand specific weakness classes associated with DrayTek products, helping security professionals identify patterns in software development or configuration errors that may recur across different models. By examining the vulnerability history of specific DrayTek devices, administrators can better assess risk exposure for their current deployments and plan appropriate mitigation strategies or firmware upgrades. This centralized view eliminates the need to scour multiple sources for patch notes, offering a clear narrative of security evolution for the DrayTek ecosystem. It serves as a reference for security auditors, IT managers, and researchers interested in the lifecycle of security defects within these specific networking solutions, facilitating informed decision-making regarding product selection and ongoing maintenance protocols without relying on scattered or outdated information sources.

Found 29 results / 40 Clear Filters
Top products by DrayTek Corporation: VigorSwitch G2540xs VigorAP 918R Vigor1000B
CVE ID Title CVSS Severity Published
CVE-2026-71943 DrayTek VigorSwitch Multiple Models OS Command Injection via setDevNet — VigorSwitch G2540xs CWE-78 7.2 High 2026-08-24
CVE-2026-71942 DrayTek VigorSwitch Multiple Models Buffer Overflow via mail_mailalert — VigorSwitch G2540xs CWE-120 7.2 High 2026-08-24
CVE-2026-71941 DrayTek VigorSwitch Multiple Models Buffer Overflow via diag_logmail — VigorSwitch G2540xs CWE-120 7.2 High 2026-08-24
CVE-2026-71940 DrayTek VigorSwitch Multiple Models Buffer Overflow via acl_general_setup Edit ACE — VigorSwitch G2540xs CWE-120 7.2 High 2026-08-24
CVE-2026-71939 DrayTek VigorSwitch Multiple Models Buffer Overflow via acl_general_setup Add ACE — VigorSwitch G2540xs CWE-120 7.2 High 2026-08-24
CVE-2026-71938 DrayTek VigorSwitch Multiple Models Buffer Overflow via switch_lan_gvrp — VigorSwitch G2540xs CWE-120 7.2 High 2026-08-24
CVE-2026-71937 DrayTek VigorSwitch Multiple Models Buffer Overflow via poe_schedule_profile — VigorSwitch G2540xs CWE-120 7.2 High 2026-08-24
CVE-2026-71936 DrayTek VigorSwitch Multiple Models Buffer Overflow via sysreboot — VigorSwitch G2540xs CWE-120 7.2 High 2026-08-24
CVE-2026-71934 DrayTek VigorSwitch Multiple Models Buffer Overflow via pingtrace — VigorSwitch G2540xs CWE-120 7.2 High 2026-08-24
CVE-2026-71935 DrayTek VigorSwitch Multiple Models Buffer Overflow via webBackupAction — VigorSwitch G2540xs CWE-120 7.2 High 2026-08-24
CVE-2026-71933 DrayTek VigorSwitch Multiple Models Missing Authorization in Syslog Functions — VigorSwitch G2540xs CWE-862 9.1 Critical 2026-08-24
CVE-2026-71931 DrayTek VigorSwitch Multiple Models OS Command Injection via tftp_upgrade — VigorSwitch G2540xs CWE-78 7.2 High 2026-08-24
CVE-2026-71932 DrayTek VigorSwitch Multiple Models Path Traversal via getSyslogFile — VigorSwitch G2540xs CWE-22 4.9 Medium 2026-08-24
CVE-2026-71930 DrayTek VigorSwitch Multiple Models OS Command Injection via setTime — VigorSwitch G2540xs CWE-78 7.2 High 2026-08-24
CVE-2026-71928 DrayTek VigorSwitch Multiple Models OS Command Injection via fdftDevice — VigorSwitch G2540xs CWE-78 7.2 High 2026-08-24
CVE-2026-71929 DrayTek VigorSwitch Multiple Models OS Command Injection via setDevProto — VigorSwitch G2540xs CWE-78 7.2 High 2026-08-24
CVE-2026-71927 DrayTek VigorSwitch Multiple Models OS Command Injection via rebDevice — VigorSwitch G2540xs CWE-78 7.2 High 2026-08-24
CVE-2026-71925 DrayTek VigorSwitch Multiple Models OS Command Injection via getDetail — VigorSwitch G2540xs CWE-78 7.2 High 2026-08-24
CVE-2026-71926 DrayTek VigorSwitch Multiple Models OS Command Injection via setDevice — VigorSwitch G2540xs CWE-78 7.2 High 2026-08-24
CVE-2026-71924 DrayTek VigorSwitch Multiple Models OS Command Injection via getVid — VigorSwitch G2540xs CWE-78 7.2 High 2026-08-24
CVE-2026-71922 DrayTek VigorSwitch Multiple Models Pre-Authentication NULL Pointer Dereference via setget.cgi — VigorSwitch G2540xs CWE-476 7.5 High 2026-08-24
CVE-2026-71923 DrayTek VigorSwitch Multiple Models OS Command Injection via auth_set — VigorSwitch G2540xs CWE-78 7.2 High 2026-08-24
CVE-2026-71921 DrayTek VigorSwitch Multiple Models Pre-Authentication OS Command Injection via setget.cgi — VigorSwitch G2540xs CWE-78 9.8 Critical 2026-08-24
CVE-2026-71919 DrayTek VigorSwitch Multiple Models OS Command Injection via sysreboot — VigorSwitch G2540xs CWE-78 7.2 High 2026-08-24
CVE-2026-71920 DrayTek VigorSwitch Multiple Models NULL Pointer Dereference via formlogout — VigorSwitch G2540xs CWE-476 4.9 Medium 2026-08-24
CVE-2026-71918 DrayTek VigorSwitch Multiple Models OS Command Injection via webBackupAction — VigorSwitch G2540xs CWE-78 7.2 High 2026-08-24
CVE-2026-71917 DrayTek VigorSwitch Multiple Models OS Command Injection via pingtrace — VigorSwitch G2540xs CWE-78 7.2 High 2026-08-24
CVE-2026-71916 DrayTek VigorSwitch Multiple Models OS Command Injection via commandTable — VigorSwitch G2540xs CWE-78 7.2 High 2026-08-24
CVE-2026-71915 DrayTek VigorSwitch Multiple Models OS Command Injection via jsonstatus — VigorSwitch G2540xs CWE-78 7.2 High 2026-08-24

This page lists every published CVE security advisory associated with DrayTek Corporation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.