
DrayTek Security Advisory Updates (12/08/26)
1. Command Injection and Buffer Overflow in DrayTek Vigor Access Points
DrayTek has found several security vulnerabilities in the VigorAP series, such as Command Injection and Buffer Overflow.
CVE IDENTIFIERS: CVE-2026-71904 ~ CVE-2026-71914
While these conditions have been verified in affected firmware, there are no known methods to trigger or exploit them, and no practical attack path has been identified. Therefore, there is no current evidence that these issues can be exploited in real-world settings.
DrayTek has issued a firmware update for several Vigor Access Points to avoid possible problems.
The updated firmware is available to download from our support page:
https://www.draytek.com.au/support/downloads/
Affected Models & Recommended Firmware
| Model | Updated Firmware Version |
|---|---|
| VigorAP 918 | 1.4.11 |
| VigorAP 960 / 1060C | 1.4.12 |
| VigorAP 906 | 1.4.13 |
| VigorAP 912C | 1.4.15 |
| VigorAP 903 | 1.4.22 |
2. Remote Code Execution and Buffer Overflow Vulnerabilities in VigorSwitches
DrayTek has published details of this security advisory on their website:
Identified CVE IDs are:
CVE-2026-52497
CVE-2026-52498
CVE-2026-52499
CVE-2026-52500
CVE-2026-52501
CVE-2026-52502
CVE-2026-52503
It is recommended to update the firmware on affected VigorSwitches indicated in the table below:
| Affected VigorSwitch Models | Updated Firmware Version |
|---|---|
| VigorSwitch Q2300x / PQ2300xb | 2.10.7 |
| VigorSwitch G2282x / P2282x | 2.10.6 |
| VigorSwitch G2542x / P2542x / P2542xh | 3.10.6 |
| VigorSwitch FX2120 / P2540xs / G2540xs | 3.9.10 |
| VigorSwitch G1280 / P1280 / P1281x / G1282 / P1282 / G2100 / P2100 / G2121 / P2121 / PQ2121x / Q2121x / PQ2200xb / Q2200x / G2280x / P2280x / G2540x / P2540x | 2.9.10 |
The firmware is available to download from our support page: