DrayTek Corporation VigorSwitch G2280x

Published Atomicorp research notes for CVEs affecting DrayTek Corporation VigorSwitch G2280x where WAF protections were observed during testing or engineering review.

These notes are not intended to represent the full set of vulnerabilities mitigated by Atomicorp products and should not be interpreted as a coverage matrix, certification list, or census of protected CVEs.

Atomicorp WAF protections are primarily designed around attack techniques and exploit behaviors rather than individual vulnerability identifiers. A published research note documents a positive research finding related to that CVE. If a CVE is absent from these notes, no conclusion should be drawn about protection status.

CVEVulnerabilityCVSSSeverityRules Observed
CVE-2026-71921DrayTek VigorSwitch Multiple Models Pre-Authentication OS Command Injection via setget.cgi9.3 (v4.0)Critical340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-71915DrayTek VigorSwitch Multiple Models OS Command Injection via jsonstatus8.6 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-71918DrayTek VigorSwitch Multiple Models OS Command Injection via webBackupAction8.6 (v4.0)High340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-71919DrayTek VigorSwitch Multiple Models OS Command Injection via sysreboot8.6 (v4.0)High340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 390904 , 393655
CVE-2026-71923DrayTek VigorSwitch Multiple Models OS Command Injection via auth_set8.6 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-71924DrayTek VigorSwitch Multiple Models OS Command Injection via getVid8.6 (v4.0)High340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-71925DrayTek VigorSwitch Multiple Models OS Command Injection via getDetail8.6 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-71926DrayTek VigorSwitch Multiple Models OS Command Injection via setDevice8.6 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-71927DrayTek VigorSwitch Multiple Models OS Command Injection via rebDevice8.6 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-71928DrayTek VigorSwitch Multiple Models OS Command Injection via fdftDevice8.6 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-71929DrayTek VigorSwitch Multiple Models OS Command Injection via setDevProto8.6 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-71930DrayTek VigorSwitch Multiple Models OS Command Injection via setTime8.6 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-71931DrayTek VigorSwitch Multiple Models OS Command Injection via tftp_upgrade8.6 (v4.0)High340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-71943DrayTek VigorSwitch Multiple Models OS Command Injection via setDevNet8.6 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-71932DrayTek VigorSwitch Multiple Models Path Traversal via getSyslogFile6.9 (v4.0)Medium340007 , 344360 , 347009 , 390709