Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 24 Aug 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Multiple DrayTek VigorAP models contain a buffer overflow vulnerability in the setLan function. The vulnerability is caused by missing length checks during memory copy operations involving the lanVlanId0, lanIp, and lanNetmask fields. A remote attacker can trigger this vulnerability via crafted input, causing a denial of service or potentially executing arbitrary commands. Exploitation requires valid administrative credentials for the device's web management interface. | |
| Title | DrayTek VigorAP Multiple Models Buffer Overflow via setLan | |
| First Time appeared |
Draytek
Draytek vigorap 1060c Firmware Draytek vigorap 903 Firmware Draytek vigorap 906 Firmware Draytek vigorap 912c Firmware Draytek vigorap 918r Firmware Draytek vigorap 960c Firmware |
|
| Weaknesses | CWE-120 | |
| CPEs | cpe:2.3:o:draytek:vigorap_1060c_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:draytek:vigorap_903_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:draytek:vigorap_906_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:draytek:vigorap_912c_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:draytek:vigorap_918r_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:draytek:vigorap_960c_firmware:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Draytek
Draytek vigorap 1060c Firmware Draytek vigorap 903 Firmware Draytek vigorap 906 Firmware Draytek vigorap 912c Firmware Draytek vigorap 918r Firmware Draytek vigorap 960c Firmware |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-24T17:07:44.256Z
Reserved: 2026-08-08T16:37:44.517Z
Link: CVE-2026-71911
No data.
Status : Received
Published: 2026-08-24T18:17:02.947
Modified: 2026-08-24T18:17:02.947
Link: CVE-2026-71911
No data.
OpenCVE Enrichment
No data.
-
CWE-120
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')