Multiple DrayTek VigorSwitch models contain a null pointer dereference vulnerability in the formlogout function. The vulnerability is caused by missing checks for an empty or absent Cookie header before string handling. A remote attacker can trigger this vulnerability via a crafted request to crash the service and cause a denial of service. Exploitation requires valid administrative credentials for the device's web management interface.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-24 18:17
Updated : 2026-08-26 17:08
NVD link : CVE-2026-71920
Mitre link : CVE-2026-71920
CVE.ORG link : CVE-2026-71920
JSON object : View
Products Affected
No product.
CWE
CWE-476
NULL Pointer Dereference
