Project Subscriptions
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 24 Aug 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 24 Aug 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Multiple DrayTek VigorAP models contain a buffer overflow vulnerability in the apautotest function. The vulnerability is caused by missing length checks during memory copy operations involving the CMD6 field. A remote attacker can trigger this vulnerability via crafted input, causing a denial of service or potentially executing arbitrary commands. Exploitation requires valid administrative credentials for the device's web management interface. | |
| Title | DrayTek VigorAP Multiple Models Buffer Overflow via apautotest | |
| First Time appeared |
Draytek
Draytek vigorap 1060c Firmware Draytek vigorap 903 Firmware Draytek vigorap 906 Firmware Draytek vigorap 912c Firmware Draytek vigorap 918r Firmware Draytek vigorap 960c Firmware |
|
| Weaknesses | CWE-120 | |
| CPEs | cpe:2.3:o:draytek:vigorap_1060c_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:draytek:vigorap_903_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:draytek:vigorap_906_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:draytek:vigorap_912c_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:draytek:vigorap_918r_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:draytek:vigorap_960c_firmware:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Draytek
Draytek vigorap 1060c Firmware Draytek vigorap 903 Firmware Draytek vigorap 906 Firmware Draytek vigorap 912c Firmware Draytek vigorap 918r Firmware Draytek vigorap 960c Firmware |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-24T19:01:02.459Z
Reserved: 2026-08-08T16:37:44.517Z
Link: CVE-2026-71912
Updated: 2026-08-24T19:00:52.221Z
Status : Received
Published: 2026-08-24T18:17:03.110
Modified: 2026-08-24T19:16:52.067
Link: CVE-2026-71912
No data.
OpenCVE Enrichment
Updated: 2026-08-24T19:00:05Z