External risk intelligence

DrayTek VigorAP Command Injection Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-71914

The vulnerability affects DrayTek VigorAP wireless access points, which are network infrastructure devices frequently deployed at the network edge or in environments where they may be reachable via network-facing components. Because these devices serve as gateways and often handle management traffic, they are commonly exposed or reachable within typical network deployments.

OS Command Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A command injection vulnerability has been identified in multiple DrayTek VigorAP models, stemming from improper handling of UDP messages. This could allow a remote attacker to execute arbitrary commands with root privileges on affected devices.

  • Unvalidated messages allow remote command execution.
  • Network devices are critical infrastructure.
  • Confirm relevance and exposure of VigorAP devices.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by sending a specially crafted UDP message to a DrayTek VigorAP wireless access point. The device's `dray_apm` component does not properly validate the content of this message before executing commands, allowing an attacker to inject and run arbitrary commands with root privileges on the device.

  • No authentication or user interaction needed.
  • Triggered by sending a crafted UDP message.
  • Allows remote code execution with root privileges.

Live Threat

Current exploitation, exposure, and threat context

A command injection vulnerability in the dray_apm component could allow an unauthenticated remote attacker to execute arbitrary commands with root privileges on affected DrayTek VigorAP models. This could occur when the device processes a crafted UDP message, potentially impacting the device's overall integrity and confidentiality.

  • Affected system data and device control.
  • Triggered by crafted UDP messages.
  • Arbitrary command execution with root privileges.

Operational Fix

Recommended remediation, mitigation, and detection steps

Systems owners and infrastructure teams are responsible for managing DrayTek VigorAP devices. The first step is to identify all deployed VigorAP devices, confirm their network reachability and business criticality, and then coordinate with the vendor or internal teams for remediation.

  • Identify all DrayTek VigorAP assets.
  • Confirm network exposure and business criticality.
  • Plan remediation with vendor coordination.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the DrayTek VigorAP series?

DrayTek VigorAP devices are wireless access points designed to extend network coverage and manage Wi-Fi connectivity in business and professional environments. These devices act as critical bridge points between wireless clients and the wired network infrastructure, often sitting at the edge to route management and data traffic.

What does CVE-2026-71914 mean?

This CVE refers to a command injection vulnerability, classified as CWE-78. In simple terms, the software fails to properly filter instructions hidden within incoming data. Because the device trusts these messages, an attacker can trick it into running unauthorized commands with the highest level of system control, known as root privileges.

How is this vulnerability triggered?

An attacker triggers the flaw by sending a specially crafted UDP message to the device. The issue specifically occurs when the system processes these messages for speed testing tasks. Simply sending standard network traffic or using other device features does not trigger the vulnerability; it requires a message specifically designed to exploit the dray_apm component.

Is my DrayTek VigorAP device at risk?

According to Halo Surface Signal, these devices are often deployed at the network edge or in reachable areas, making them likely targets for network-based attacks. If your VigorAP is configured to be accessible over the network, it faces a higher potential risk because the vulnerability does not require authentication or user interaction to succeed.

What steps should I take if I use these devices?

Begin by creating an inventory of all VigorAP units in your environment to understand your footprint. Once mapped, assess which devices are reachable over your network and prioritize them based on their importance to your operations. Finally, coordinate with your IT team or the vendor to apply the necessary security updates to close the injection path.

References