CVE-2026-71922
Severity CVSS v4.0:
HIGH
Type:
CWE-476
NULL Pointer Dereference
Publication date:
24/08/2026
Last modified:
24/08/2026
Description
Multiple DrayTek VigorSwitch models contain a pre-authentication null pointer dereference vulnerability in the setget.cgi interface. The vulnerability is caused by missing validation when the pass field is absent. A remote attacker can trigger this vulnerability via a crafted request to crash the service and cause a denial of service.
Impact
Base Score 4.0
8.70
Severity 4.0
HIGH
Base Score 3.x
7.50
Severity 3.x
HIGH



