A critical pre-authentication command injection vulnerability affects multiple DrayTek VigorSwitch models, allowing remote attackers to execute arbitrary commands with root privileges without any credentials. Given the CVSS score of 9.8 and the device's role as network infrastructure, this flaw poses an immediate risk of full network compromise. Organizations using DrayTek switches at network edges should treat this as an urgent patching priority.
Updated Aug 25, 2026 · CVSS 9.8