SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-71920

MEDIUM · CVSS 4.9 EPSS 0.39% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-24 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

Multiple DrayTek VigorSwitch models are susceptible to a null pointer dereference vulnerability in the formlogout function, which arises from inadequate checks for an empty or missing Cookie header. A remote attacker with valid administrative credentials can exploit this flaw by sending a specially crafted request, leading to a denial of service that crashes the service. Organizations using affected VigorSwitch models should prioritize addressing this vulnerability to maintain service availability and security.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-71920
Severity
MEDIUM
CVSS
4.9
EPSS
0.39%

Original NVD Description

Multiple DrayTek VigorSwitch models contain a null pointer dereference vulnerability in the formlogout function. The vulnerability is caused by missing checks for an empty or absent Cookie header before string handling. A remote attacker can trigger this vulnerability via a crafted request to crash the service and cause a denial of service. Exploitation requires valid administrative credentials for the device's web management interface.