• Aviso de Segurança – Command Injection, Null Pointer Dereference, Directory Traversal e Buffer Overflow

No dia 1 de junho de 2026, a DrayTek identificou várias vulnerabilidades de segurança no componente mainfunction.cgi dos DrayTek VigorSwitch, incluindo Command Injection, Null Pointer Dereference, Directory Traversal e Buffer Overflow.

Embora estas condições tenham sido confirmadas no código afetado, atualmente não existem métodos conhecidos ou documentados para as ativar ou explorar, e não foi identificado nenhum método de ataque prático. Consequentemente, não há evidências, neste momento, de que os problemas reportados sejam exploráveis em ambientes implementados.

Estas vulnerabilidades foram identificadas como:

  • CVE-2026-71915 — Command Injection
  • CVE-2026-71916 — Command Injection
  • CVE-2026-71917 — Command Injection
  • CVE-2026-71918 — Command Injection
  • CVE-2026-71919 — Command Injection
  • CVE-2026-71920 — Null Pointer Dereference
  • CVE-2026-71921 — Command Injection
  • CVE-2026-71922 — Null Pointer Dereference
  • CVE-2026-71923 — Command Injection
  • CVE-2026-71924 — Command Injection
  • CVE-2026-71925 — Command Injection
  • CVE-2026-71926 — Command Injection
  • CVE-2026-71927 — Command Injection
  • CVE-2026-71928 — Command Injection
  • CVE-2026-71929 — Command Injection
  • CVE-2026-71930 — Command Injection
  • CVE-2026-71931 — Command Injection
  • CVE-2026-71932 — Directory Traversal
  • CVE-2026-71933 — Unauthorized Operation (Missing Authorization)
  • CVE-2026-71934 — Buffer Overflow
  • CVE-2026-71935 — Buffer Overflow
  • CVE-2026-71936 — Buffer Overflow
  • CVE-2026-71937 — Buffer Overflow
  • CVE-2026-71938 — Buffer Overflow
  • CVE-2026-71939 — Buffer Overflow
  • CVE-2026-71940 — Buffer Overflow
  • CVE-2026-71941 — Buffer Overflow
  • CVE-2026-71942 — Buffer Overflow
  • CVE-2026-71943 — Command Injection

Os novos firmwares com melhorias de segurança para estas vulnerabilidades estão disponíveis aqui .

Aviso de Segurança – Command Injection, Null Pointer Dereference, Directory Traversal e Buffer Overflow