SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-71914

CRITICAL · CVSS 9.8 EPSS 3.07%

Source: NVD + CISA KEV + EPSS · Published 2026-08-24 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Multiple DrayTek VigorAP models are susceptible to a critical command injection vulnerability in the dray_apm component, stemming from inadequate validation of UDP message content during the START_SPEED_TEST process. This flaw allows remote attackers to send specially crafted messages, potentially executing arbitrary commands with root privileges on the affected devices. Organizations using these models should prioritize immediate remediation to mitigate the risk of unauthorized access and control over their network infrastructure.

CVE
CVE-2026-71914
Severity
CRITICAL
CVSS
9.8
EPSS
3.07%

Original NVD Description

Multiple DrayTek VigorAP models contain a command injection vulnerability in the dray_apm component. The vulnerability is caused by insufficient validation of UDP message content after START_SPEED_TEST before command execution. A remote attacker can trigger this vulnerability via a crafted message to execute arbitrary commands with root privileges.