SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-71922

HIGH · CVSS 7.5 EPSS 0.47%

Source: NVD + CISA KEV + EPSS · Published 2026-08-24 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

Multiple DrayTek VigorSwitch models are vulnerable due to a pre-authentication null pointer dereference in the setget.cgi interface, which lacks proper validation when the pass field is omitted. This flaw allows remote attackers to exploit the vulnerability by sending specially crafted requests, leading to a denial of service. Organizations using affected VigorSwitch models should prioritize patching this vulnerability to prevent potential service disruptions.

CVE
CVE-2026-71922
Severity
HIGH
CVSS
7.5
EPSS
0.47%

Original NVD Description

Multiple DrayTek VigorSwitch models contain a pre-authentication null pointer dereference vulnerability in the setget.cgi interface. The vulnerability is caused by missing validation when the pass field is absent. A remote attacker can trigger this vulnerability via a crafted request to crash the service and cause a denial of service.