A critical (CVSS 9.1) missing-authorization flaw across dozens of DrayTek VigorSwitch models lets unauthenticated remote attackers alter switch configuration, restart services, and wipe logs via crafted requests.
What Is It
Multiple DrayTek VigorSwitch models contain unauthorized operation vulnerabilities in multiple syslog functions. The root cause is missing authorization checks; the affected syslog endpoints do not verify that the requester is permitted to perform the operation. A remote attacker can trigger these vulnerabilities using crafted requests to modify configuration, restart services, save startup configuration, or clear logs.
The CVSS 3.1 vector is AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H, network-reachable, low complexity, no privileges, no user interaction, with high impact to both integrity and availability. Confidentiality impact is rated none; this is a write-and-disrupt bug, not a data-theft bug.
Why It Matters
Two properties make this worse than a typical config-tampering issue. First, the ability to save startup configuration means attacker changes can survive a reboot; persistence on network infrastructure without any credential. Second, the ability to clear logs directly attacks the switch's own evidence trail, which is exactly the record a defender would consult after the other operations were abused. Combined with unauthenticated service restarts, an attacker on a reachable network path can degrade or reshape a switching layer at will.
CISA KEV: this CVE does not appear in the CISA Known Exploited Vulnerabilities catalog, so there is no confirmed active exploitation and no KEV-mandated remediation deadline at this time.
What's Vulnerable
DrayTek Corporation VigorSwitch series, with fixed versions varying by model family:
- Below 3.9.10: G2540xs, P2540xs, FX2120
- Below 3.10.6: G2542x, P2542x, P2542xh
- Below 2.10.7: Q2300x, PQ2300xb
- Below 2.10.6: G2282x, P2282x
- Below 2.9.10: PX2060, G1280, P1280, P1281x, G1282, P1282, G2121, P2121, PQ2121x, Q2121x, G2280x, P2280x, Q2200x, PQ2200xb, and additional models listed in the vendor advisory
All versions prior to the model's listed fix are affected; the supplied record marks default status as unaffected outside those ranges.
Patch Status
DrayTek has published fixed firmware; upgrade each switch to at least the version listed above for its model. The vendor's August 2026 advisory is the authoritative mapping of model to fixed release. The NVD record is in "Received" status as of 2026-08-24, so details may still change.
Sources
- DrayTek Security Advisory; Multiple Vulnerabilities in VigorSwitch Series (August 2026): https://www.draytek.com/about/security-advisory/multiple-vulnerabilities-in-vigorswitch-series-august-2026/
- VulnCheck Advisory; DrayTek VigorSwitch Multiple Models Missing Authorization in Syslog Functions: https://www.vulncheck.com/advisories/draytek-vigorswitch-multiple-models-missing-authorization-in-syslog-functions
- NVD, CVE-2026-71933: https://nvd.nist.gov/vuln/detail/CVE-2026-71933
- CISA Known Exploited Vulnerabilities Catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog