Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 24 Aug 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Multiple DrayTek VigorAP models contain a command injection vulnerability in the apautotest function. The vulnerability is caused by insufficient validation of the CMD0, CMD3, and CMD6 fields before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administrative credentials for the device's web management interface. | |
| Title | DrayTek VigorAP Multiple Models OS Command Injection via apautotest | |
| First Time appeared |
Draytek
Draytek vigorap 1060c Firmware Draytek vigorap 903 Firmware Draytek vigorap 906 Firmware Draytek vigorap 912c Firmware Draytek vigorap 918r Firmware Draytek vigorap 960c Firmware |
|
| Weaknesses | CWE-78 | |
| CPEs | cpe:2.3:o:draytek:vigorap_1060c_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:draytek:vigorap_903_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:draytek:vigorap_906_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:draytek:vigorap_912c_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:draytek:vigorap_918r_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:draytek:vigorap_960c_firmware:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Draytek
Draytek vigorap 1060c Firmware Draytek vigorap 903 Firmware Draytek vigorap 906 Firmware Draytek vigorap 912c Firmware Draytek vigorap 918r Firmware Draytek vigorap 960c Firmware |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-24T17:07:43.597Z
Reserved: 2026-08-08T16:37:44.517Z
Link: CVE-2026-71910
No data.
Status : Received
Published: 2026-08-24T18:17:02.770
Modified: 2026-08-24T18:17:02.770
Link: CVE-2026-71910
No data.
OpenCVE Enrichment
No data.