← Back to overview

Multiple DrayTek VigorSwitch models are affected by unauthorized operation vulnerabilities in several syslog functions. The root cause is missing authorization checks, allowing remote attackers to perform sensitive operations without authentication. Attackers can craft malicious requests to modify device configuration, restart services, save startup configuration, or clear logs. The vulnerability poses significant risk to network infrastructure as it can be exploited remotely without credentials. DrayTek has published a security advisory addressing these issues in August 2026. The flaw is classified under missing authorization (CWE-862) and impacts network switch management integrity and availability.

Affected products

  • DrayTek VigorSwitch

Related CVE's

  • CVE-2026-71933

Categories

  • Identity & Access
  • Network Infrastructure