Multiple DrayTek VigorSwitch models are affected by a critical pre-authentication command injection vulnerability tracked as CVE-2026-71921. The flaw resides in the setget.cgi interface and is caused by insufficient input filtering of the 'pass' field prior to command execution. A remote, unauthenticated attacker can exploit this vulnerability by sending crafted input to execute arbitrary operating system commands with root privileges. No authentication is required to trigger the vulnerability, making it particularly dangerous for internet-exposed devices. DrayTek has published a security advisory acknowledging the issue. The vulnerability impacts the VigorSwitch product series and poses significant risk to network infrastructure environments. Organizations using affected DrayTek VigorSwitch models are advised to apply patches or mitigations immediately.