Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.2 HIGH
CVE-2026-71938 — DrayTek VigorSwitch Multiple Models Buffer Overflow via switch_lan_gvrp

Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the switch_lan_gvrp function. The vulnerability is caused by unsafe copying of the portList field into an undersized buf…

Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
8.6 HIGH
CVE-2026-71937 — DrayTek VigorSwitch Multiple Models Buffer Overflow via poe_schedule_profile

Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the poe_schedule_profile function. The vulnerability is caused by repeated concatenation of the start_date, start_time, …

Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
7.2 HIGH
CVE-2026-71936 — DrayTek VigorSwitch Multiple Models Buffer Overflow via sysreboot

Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the sysreboot function. The vulnerability is caused by unsafe concatenation of split valueN data into a fixed-size buffe…

Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
8.6 HIGH
CVE-2026-71935 — DrayTek VigorSwitch Multiple Models Buffer Overflow via webBackupAction

Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the webBackupAction function. The vulnerability is caused by repeated string concatenation of the pathN, valueN, key, an…

Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
8.6 HIGH
CVE-2026-71934 — DrayTek VigorSwitch Multiple Models Buffer Overflow via pingtrace

Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the pingtrace function. The vulnerability is caused by missing length checks when the host, count, and interval fields a…

Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
9.1 CRITICAL
CVE-2026-71933 — DrayTek VigorSwitch Multiple Models Missing Authorization in Syslog Functions

Multiple DrayTek VigorSwitch models contain unauthorized operation vulnerabilities in multiple syslog functions. The vulnerability is caused by missing authorization checks. A remote attacker can tri…

Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
6.9 MEDIUM
CVE-2026-71932 — DrayTek VigorSwitch Multiple Models Path Traversal via getSyslogFile

Multiple DrayTek VigorSwitch models contain a directory traversal vulnerability in the getSyslogFile function. The vulnerability is caused by insufficient validation of the option field. A remote att…

Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
7.2 HIGH
CVE-2026-71931 — DrayTek VigorSwitch Multiple Models OS Command Injection via tftp_upgrade

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the tftp_upgrade function. The vulnerability is caused by insufficient filtering before the filename field is concaten…

Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
7.2 HIGH
CVE-2026-71930 — DrayTek VigorSwitch Multiple Models OS Command Injection via setTime

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setTime function. The vulnerability is caused by insufficient filtering of the username and password fields before…

Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
8.6 HIGH
CVE-2026-71929 — DrayTek VigorSwitch Multiple Models OS Command Injection via setDevProto

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setDevProto function. The vulnerability is caused by insufficient filtering of the username and password fields be…

Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
7.2 HIGH
CVE-2026-71928 — DrayTek VigorSwitch Multiple Models OS Command Injection via fdftDevice

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the fdftDevice function. The vulnerability is caused by insufficient filtering of the username and password fields bef…

Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
8.6 HIGH
CVE-2026-71927 — DrayTek VigorSwitch Multiple Models OS Command Injection via rebDevice

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the rebDevice function. The vulnerability is caused by insufficient filtering of the username and password fields befo…

Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
7.2 HIGH
CVE-2026-71926 — DrayTek VigorSwitch Multiple Models OS Command Injection via setDevice

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setDevice function. The vulnerability is caused by insufficient sanitization of the username, password, and locati…

Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
8.6 HIGH
CVE-2026-71925 — DrayTek VigorSwitch Multiple Models OS Command Injection via getDetail

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the getDetail function. The vulnerability is caused by insufficient filtering of the username and password fields befo…

Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
8.6 HIGH
CVE-2026-71924 — DrayTek VigorSwitch Multiple Models OS Command Injection via getVid

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the getVid function. The vulnerability is caused by insufficient filtering of the username and password fields before …

Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
7.2 HIGH
CVE-2026-71923 — DrayTek VigorSwitch Multiple Models OS Command Injection via auth_set

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the auth_set function. The vulnerability is caused by insufficient filtering of the username and password fields befor…

Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
8.7 HIGH
CVE-2026-71922 — DrayTek VigorSwitch Multiple Models Pre-Authentication NULL Pointer Dereference via setge…

Multiple DrayTek VigorSwitch models contain a pre-authentication null pointer dereference vulnerability in the setget.cgi interface. The vulnerability is caused by missing validation when the pass fi…

Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
9.8 CRITICAL
CVE-2026-71921 — DrayTek VigorSwitch Multiple Models Pre-Authentication OS Command Injection via setget.cgi

Multiple DrayTek VigorSwitch models contain a pre-authentication command injection vulnerability in the setget.cgi interface. The vulnerability is caused by insufficient filtering of the pass field b…

Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
6.9 MEDIUM
CVE-2026-71920 — DrayTek VigorSwitch Multiple Models NULL Pointer Dereference via formlogout

Multiple DrayTek VigorSwitch models contain a null pointer dereference vulnerability in the formlogout function. The vulnerability is caused by missing checks for an empty or absent Cookie header bef…

Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
8.6 HIGH
CVE-2026-71919 — DrayTek VigorSwitch Multiple Models OS Command Injection via sysreboot

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the sysreboot function. The vulnerability is caused by insufficient filtering of the config, act, pathN, and valueN fi…

Aug 24, 2026 Aug 24, 2026
Aug 24, 2026
Aug 24, 2026
Showing 20 of 11523 Results