DrayTek Corporation VigorSwitch G2121
Published Atomicorp research notes for CVEs affecting DrayTek Corporation VigorSwitch G2121 where WAF protections were observed during testing or engineering review.
These notes are not intended to represent the full set of vulnerabilities mitigated by Atomicorp products and should not be interpreted as a coverage matrix, certification list, or census of protected CVEs.
Atomicorp WAF protections are primarily designed around attack techniques and exploit behaviors rather than individual vulnerability identifiers. A published research note documents a positive research finding related to that CVE. If a CVE is absent from these notes, no conclusion should be drawn about protection status.
| CVE | Vulnerability | CVSS | Severity | Rules Observed |
|---|---|---|---|---|
| CVE-2026-71921 | DrayTek VigorSwitch Multiple Models Pre-Authentication OS Command Injection via setget.cgi | 9.3 (v4.0) | Critical | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-71915 | DrayTek VigorSwitch Multiple Models OS Command Injection via jsonstatus | 8.6 (v4.0) | High | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-71918 | DrayTek VigorSwitch Multiple Models OS Command Injection via webBackupAction | 8.6 (v4.0) | High | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-71919 | DrayTek VigorSwitch Multiple Models OS Command Injection via sysreboot | 8.6 (v4.0) | High | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 390904 , 393655 |
| CVE-2026-71923 | DrayTek VigorSwitch Multiple Models OS Command Injection via auth_set | 8.6 (v4.0) | High | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-71924 | DrayTek VigorSwitch Multiple Models OS Command Injection via getVid | 8.6 (v4.0) | High | 340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-71925 | DrayTek VigorSwitch Multiple Models OS Command Injection via getDetail | 8.6 (v4.0) | High | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-71926 | DrayTek VigorSwitch Multiple Models OS Command Injection via setDevice | 8.6 (v4.0) | High | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-71927 | DrayTek VigorSwitch Multiple Models OS Command Injection via rebDevice | 8.6 (v4.0) | High | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-71928 | DrayTek VigorSwitch Multiple Models OS Command Injection via fdftDevice | 8.6 (v4.0) | High | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-71929 | DrayTek VigorSwitch Multiple Models OS Command Injection via setDevProto | 8.6 (v4.0) | High | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-71930 | DrayTek VigorSwitch Multiple Models OS Command Injection via setTime | 8.6 (v4.0) | High | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-71931 | DrayTek VigorSwitch Multiple Models OS Command Injection via tftp_upgrade | 8.6 (v4.0) | High | 340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-71943 | DrayTek VigorSwitch Multiple Models OS Command Injection via setDevNet | 8.6 (v4.0) | High | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-71932 | DrayTek VigorSwitch Multiple Models Path Traversal via getSyslogFile | 6.9 (v4.0) | Medium | 340007 , 344360 , 347009 , 390709 |