CyberRota Analysis
AI-GeneratedMultiple DrayTek VigorSwitch models are vulnerable due to a pre-authentication null pointer dereference in the setget.cgi interface, which lacks proper validation when the pass field is omitted. This flaw allows remote attackers to exploit the vulnerability by sending specially crafted requests, leading to a denial of service. Organizations using affected VigorSwitch models should prioritize patching this vulnerability to prevent potential service disruptions.
Original NVD Description
Multiple DrayTek VigorSwitch models contain a pre-authentication null pointer dereference vulnerability in the setget.cgi interface. The vulnerability is caused by missing validation when the pass field is absent. A remote attacker can trigger this vulnerability via a crafted request to crash the service and cause a denial of service.