SYS::ONLINE
Wasteland.
Briefs2241
Issues25
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-71933 2026-08-24

CVE-2026-71933: Missing Authorization in DrayTek VigorSwitch Syslog Functions

"A critical (CVSS 9.1) missing-authorization flaw across dozens of DrayTek VigorSwitch models lets unauthenticated remote attackers alter switch configuration, restart services, and wipe logs via crafted requests."

A critical (CVSS 9.1) missing-authorization flaw across dozens of DrayTek VigorSwitch models lets unauthenticated remote attackers alter switch configuration, restart services, and wipe logs via crafted requests.

What Is It

Multiple DrayTek VigorSwitch models contain unauthorized operation vulnerabilities in multiple syslog functions. The root cause is missing authorization checks; the affected syslog endpoints do not verify that the requester is permitted to perform the operation. A remote attacker can trigger these vulnerabilities using crafted requests to modify configuration, restart services, save startup configuration, or clear logs.

The CVSS 3.1 vector is AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H, network-reachable, low complexity, no privileges, no user interaction, with high impact to both integrity and availability. Confidentiality impact is rated none; this is a write-and-disrupt bug, not a data-theft bug.

Why It Matters

Two properties make this worse than a typical config-tampering issue. First, the ability to save startup configuration means attacker changes can survive a reboot; persistence on network infrastructure without any credential. Second, the ability to clear logs directly attacks the switch's own evidence trail, which is exactly the record a defender would consult after the other operations were abused. Combined with unauthenticated service restarts, an attacker on a reachable network path can degrade or reshape a switching layer at will.

CISA KEV: this CVE does not appear in the CISA Known Exploited Vulnerabilities catalog, so there is no confirmed active exploitation and no KEV-mandated remediation deadline at this time.

What's Vulnerable

DrayTek Corporation VigorSwitch series, with fixed versions varying by model family:

All versions prior to the model's listed fix are affected; the supplied record marks default status as unaffected outside those ranges.

Patch Status

DrayTek has published fixed firmware; upgrade each switch to at least the version listed above for its model. The vendor's August 2026 advisory is the authoritative mapping of model to fixed release. The NVD record is in "Received" status as of 2026-08-24, so details may still change.

Sources