CVE-2026-71920: DrayTek Corporation Vigorswitch FX2120

Medium severity, CVSS 4.9. EPSS: 0.6% chance of exploitation in the next 30 days.

Multiple DrayTek VigorSwitch models contain a null pointer dereference vulnerability in the formlogout function. The vulnerability is caused by missing checks for an empty or absent Cookie header before string handling. A remote attacker can trigger this vulnerability via a crafted request to crash the service and cause a denial of service. Exploitation requires valid administrative credentials for the device's web management interface.

Affected products

Published 2026-08-24. Last modified 2026-08-26.