DrayTek Security Advisory Updates

DrayTek Security Advisory Updates (12/08/26)

1. Command Injection and Buffer Overflow in DrayTek Vigor Access Points

DrayTek has found several security vulnerabilities in the VigorAP series, such as Command Injection and Buffer Overflow.

CVE IDENTIFIERS: CVE-2026-71904 ~ CVE-2026-71914

While these conditions have been verified in affected firmware, there are no known methods to trigger or exploit them, and no practical attack path has been identified. Therefore, there is no current evidence that these issues can be exploited in real-world settings.

DrayTek has issued a firmware update for several Vigor Access Points to avoid possible problems.

The updated firmware is available to download from our support page:

https://www.draytek.com.au/support/downloads/

Affected Models & Recommended Firmware

ModelUpdated Firmware Version
VigorAP 9181.4.11
VigorAP 960 / 1060C1.4.12
VigorAP 9061.4.13
VigorAP 912C1.4.15
VigorAP 9031.4.22

2. Remote Code Execution and Buffer Overflow Vulnerabilities in VigorSwitches

DrayTek has published details of this security advisory on their website:

https://www.draytek.com/about/security-advisory/multiple-remote-code-execution-and-buffer-overflow-vulnerabilities-july-2026.

Identified CVE IDs are:

CVE-2026-52497
CVE-2026-52498
CVE-2026-52499
CVE-2026-52500
CVE-2026-52501
CVE-2026-52502
CVE-2026-52503

It is recommended to update the firmware on affected VigorSwitches indicated in the table below:

Affected VigorSwitch ModelsUpdated Firmware Version
VigorSwitch Q2300x / PQ2300xb2.10.7
VigorSwitch G2282x / P2282x2.10.6
VigorSwitch G2542x / P2542x / P2542xh3.10.6
VigorSwitch FX2120 / P2540xs / G2540xs3.9.10
VigorSwitch G1280 / P1280 / P1281x / G1282 / P1282 / G2100 / P2100 / G2121 / P2121 / PQ2121x / Q2121x / PQ2200xb / Q2200x / G2280x / P2280x / G2540x / P2540x2.9.10

The firmware is available to download from our support page:

https://www.draytek.com.au/support/downloads/