CyberRota Analysis
AI-GeneratedMultiple DrayTek VigorSwitch models are susceptible to a null pointer dereference vulnerability in the formlogout function, which arises from inadequate checks for an empty or missing Cookie header. A remote attacker with valid administrative credentials can exploit this flaw by sending a specially crafted request, leading to a denial of service that crashes the service. Organizations using affected VigorSwitch models should prioritize addressing this vulnerability to maintain service availability and security.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Multiple DrayTek VigorSwitch models contain a null pointer dereference vulnerability in the formlogout function. The vulnerability is caused by missing checks for an empty or absent Cookie header before string handling. A remote attacker can trigger this vulnerability via a crafted request to crash the service and cause a denial of service. Exploitation requires valid administrative credentials for the device's web management interface.