CVE-2026-71904
Multiple DrayTek VigorAP models contain a command injection vulnerability in the tr069TestInform function. The vulnerability is caused by insufficient filtering of dangerous characters before the event_code field is concatenated into a system command. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administrative credentials for the device's web management interface.
Published:Aug 24, 2026
Last Modified:Aug 24, 2026
EPS:Aug 24, 2026
EPSS Score:
CVSS Score:7.2
Affected Products
Vendor
Product
Action
Vendor
Draytek
Product
Vigorap 1060c
Draytek
Vigorap 1060c
Vendor
Draytek
Product
Vigorap 1060c Firmware
Draytek
Vigorap 1060c Firmware
Vendor
Draytek
Product
Vigorap 903
Draytek
Vigorap 903
Vendor
Draytek
Product
Vigorap 903 Firmware
Draytek
Vigorap 903 Firmware
Vendor
Draytek
Product
Vigorap 906
Draytek
Vigorap 906
Vendor
Draytek
Product
Vigorap 906 Firmware
Draytek
Vigorap 906 Firmware
Vendor
Draytek
Product
Vigorap 912c
Draytek
Vigorap 912c
Vendor
Draytek
Product
Vigorap 912c Firmware
Draytek
Vigorap 912c Firmware
Vendor
Draytek
Product
Vigorap 918r
Draytek
Vigorap 918r
Vendor
Draytek
Product
Vigorap 918r Firmware
Draytek
Vigorap 918r Firmware
Vendor
Draytek
Product
Vigorap 960c
Draytek
Vigorap 960c
Vendor
Draytek
Product
Vigorap 960c Firmware
Draytek
Vigorap 960c Firmware
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
