Horizon Alert
Summary of the vulnerability and why it matters
A critical command injection vulnerability has been identified in multiple DrayTek VigorSwitch models, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges through the setget.cgi interface. The core issue stems from insufficient input filtering, which attackers can exploit by sending specially crafted data. This presents a significant risk to the integrity and control of affected network devices.
- Attackers can run any command on vulnerable devices.
- This impacts core network infrastructure and potential pivots.
- Confirm exposure; address if present on your network.
Attack Path
How an attacker could exploit the issue
An attacker can exploit this vulnerability by sending specially crafted input to the `setget.cgi` interface on vulnerable DrayTek VigorSwitch devices. Because this interface is pre-authentication and lacks sufficient input filtering, the attacker can inject commands that are then executed with root privileges on the device. This could allow the attacker to take complete control of the affected switch.
- No authentication required.
- Triggered via crafted input to `setget.cgi`.
- Enables arbitrary command execution as root.
Live Threat
Current exploitation, exposure, and threat context
This vulnerability could allow an unauthenticated remote attacker to execute arbitrary commands with root privileges on affected network devices when the `setget.cgi` interface is accessible.
- System commands could be executed.
- Via crafted input to `setget.cgi`.
- Compromise of device functionality.
Operational Fix
Recommended remediation, mitigation, and detection steps
Teams responsible for network infrastructure and device management should prioritize this vulnerability. The first practical step is to identify all DrayTek VigorSwitch models deployed within your environment, determine their internet or cross-segment reachability, confirm their business criticality, and then assign ownership for remediation planning based on risk.
- Network and security teams should own the issue.
- Verify internet or cross-segment exposure first.
- Plan remediation based on criticality and exposure.