Multiple DrayTek VigorAP models are affected by a critical command injection vulnerability identified as CVE-2026-71914. The flaw resides in the dray_apm component and is triggered by insufficient validation of UDP message content following the START_SPEED_TEST command. A remote, unauthenticated attacker can send a specially crafted UDP message to exploit this vulnerability. Successful exploitation allows arbitrary command execution with root privileges on the affected device. The vulnerability requires no authentication, making it particularly dangerous for internet-exposed devices. DrayTek has published a security advisory acknowledging the issue and providing guidance. VulnCheck has also published an advisory detailing the pre-authentication nature of the exploit. This vulnerability poses a significant risk to network infrastructure environments where VigorAP access points are deployed. Administrators are strongly advised to apply patches or mitigations as soon as they become available.