Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.1 CRITICAL
CVE-2026-71933 — DrayTek VigorSwitch Multiple Models Missing Authorization in Syslog Functions

Multiple DrayTek VigorSwitch models contain unauthorized operation vulnerabilities in multiple syslog functions. The vulnerability is caused by missing authorization checks. A remote attacker can tri…

Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
6.9 MEDIUM
CVE-2026-71932 — DrayTek VigorSwitch Multiple Models Path Traversal via getSyslogFile

Multiple DrayTek VigorSwitch models contain a directory traversal vulnerability in the getSyslogFile function. The vulnerability is caused by insufficient validation of the option field. A remote att…

Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
7.2 HIGH
CVE-2026-71931 — DrayTek VigorSwitch Multiple Models OS Command Injection via tftp_upgrade

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the tftp_upgrade function. The vulnerability is caused by insufficient filtering before the filename field is concaten…

Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
7.2 HIGH
CVE-2026-71930 — DrayTek VigorSwitch Multiple Models OS Command Injection via setTime

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setTime function. The vulnerability is caused by insufficient filtering of the username and password fields before…

Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
8.6 HIGH
CVE-2026-71929 — DrayTek VigorSwitch Multiple Models OS Command Injection via setDevProto

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setDevProto function. The vulnerability is caused by insufficient filtering of the username and password fields be…

Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
7.2 HIGH
CVE-2026-71928 — DrayTek VigorSwitch Multiple Models OS Command Injection via fdftDevice

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the fdftDevice function. The vulnerability is caused by insufficient filtering of the username and password fields bef…

Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
8.6 HIGH
CVE-2026-71927 — DrayTek VigorSwitch Multiple Models OS Command Injection via rebDevice

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the rebDevice function. The vulnerability is caused by insufficient filtering of the username and password fields befo…

Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
7.2 HIGH
CVE-2026-71926 — DrayTek VigorSwitch Multiple Models OS Command Injection via setDevice

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setDevice function. The vulnerability is caused by insufficient sanitization of the username, password, and locati…

Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
8.6 HIGH
CVE-2026-71925 — DrayTek VigorSwitch Multiple Models OS Command Injection via getDetail

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the getDetail function. The vulnerability is caused by insufficient filtering of the username and password fields befo…

Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
8.6 HIGH
CVE-2026-71924 — DrayTek VigorSwitch Multiple Models OS Command Injection via getVid

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the getVid function. The vulnerability is caused by insufficient filtering of the username and password fields before …

Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
7.2 HIGH
CVE-2026-71923 — DrayTek VigorSwitch Multiple Models OS Command Injection via auth_set

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the auth_set function. The vulnerability is caused by insufficient filtering of the username and password fields befor…

Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
8.7 HIGH
CVE-2026-71922 — DrayTek VigorSwitch Multiple Models Pre-Authentication NULL Pointer Dereference via setge…

Multiple DrayTek VigorSwitch models contain a pre-authentication null pointer dereference vulnerability in the setget.cgi interface. The vulnerability is caused by missing validation when the pass fi…

Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
9.8 CRITICAL
CVE-2026-71921 — DrayTek VigorSwitch Multiple Models Pre-Authentication OS Command Injection via setget.cgi

Multiple DrayTek VigorSwitch models contain a pre-authentication command injection vulnerability in the setget.cgi interface. The vulnerability is caused by insufficient filtering of the pass field b…

Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
6.9 MEDIUM
CVE-2026-71920 — DrayTek VigorSwitch Multiple Models NULL Pointer Dereference via formlogout

Multiple DrayTek VigorSwitch models contain a null pointer dereference vulnerability in the formlogout function. The vulnerability is caused by missing checks for an empty or absent Cookie header bef…

Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
8.6 HIGH
CVE-2026-71919 — DrayTek VigorSwitch Multiple Models OS Command Injection via sysreboot

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the sysreboot function. The vulnerability is caused by insufficient filtering of the config, act, pathN, and valueN fi…

Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
7.2 HIGH
CVE-2026-71918 — DrayTek VigorSwitch Multiple Models OS Command Injection via webBackupAction

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the webBackupAction function. The vulnerability is caused by insufficient filtering of the option, key, pw_encode, pat…

Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
8.6 HIGH
CVE-2026-71917 — DrayTek VigorSwitch Multiple Models OS Command Injection via pingtrace

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the pingtrace function. The vulnerability is caused by insufficient validation of the host field before command execut…

Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
7.2 HIGH
CVE-2026-71916 — DrayTek VigorSwitch Multiple Models OS Command Injection via commandTable

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the commandTable function. The vulnerability is caused by incomplete filtering of dangerous characters such as backtic…

Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
8.6 HIGH
CVE-2026-71915 — DrayTek VigorSwitch Multiple Models OS Command Injection via jsonstatus

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the jsonstatus function. The vulnerability is caused by insufficient filtering of the usescript, usefile, and option f…

Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
9.8 CRITICAL
CVE-2026-71914 — DrayTek VigorAP Multiple Models Pre-Authentication OS Command Injection via dray_apm

Multiple DrayTek VigorAP models contain a command injection vulnerability in the dray_apm component. The vulnerability is caused by insufficient validation of UDP message content after START_SPEED_TE…

Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
Showing 20 of 11480 Results