Summary
- NCSC-NL has issued separate alerts covering serious flaws in DrayTek VigorAP wireless access points and VigorSwitch network devices.
- Some VigorSwitch weaknesses can allow dangerous commands before authentication, while VigorAP flaws may enable device takeover.
- The alerts arrive shortly after Dutch NIS2 legislation brought thousands of organisations under new security and resilience duties.
Dutch cyber authorities have warned organisations to update two widely used DrayTek networking product lines after serious vulnerabilities were found in wireless access points and network switches.
The Netherlands National Cyber Security Centre issued separate alerts on 26 August for DrayTek VigorAP and VigorSwitch products. The agency assessed both sets of vulnerabilities as having a medium likelihood of exploitation but potentially high impact.
VigorAP devices provide wireless connectivity into business networks, putting them in a position where compromise can expose more than the access point itself. NCSC-NL said the disclosed flaws could allow an attacker to take full control of affected equipment, disrupt network availability, gain access to data, or use the compromised device as a route for further activity inside an organisation.
The VigorSwitch warning describes a similarly serious range of outcomes. According to the NCSC, some vulnerabilities can allow commands to be executed with full administrative privileges before authentication. Others may cause a device to crash, expose confidential files, or permit unauthorised changes or restarts after an attacker has obtained administrative credentials.
DrayTek has released security updates for the affected products, and the Dutch authority is advising users to install them. The two NCSC alerts do not report active exploitation, making the current issue one of serious exposure rather than a confirmed campaign against DrayTek installations.
Network equipment occupies an unusually sensitive part of an enterprise environment. Wireless access points and switches mediate connectivity between users, systems, and other infrastructure, meaning the consequences of losing control of the device can extend beyond the appliance itself. Compromise may affect availability, traffic handling, administrative access, and the ability to trust the configuration of the network segment around it.
The alerts also land in a newly changed Dutch regulatory environment. The Netherlands’ Cyberbeveiligingswet, which implements NIS2, entered into force on 15 August and introduced security, incident reporting, governance, and resilience obligations for more than 8,000 organisations. Cyber Insider examined the start of Dutch NIS2 enforcement earlier this month.
The DrayTek alerts do not mean every organisation using the affected equipment falls within the new law, nor do they create a separate statutory requirement to patch these specific flaws. They do, however, illustrate the sort of infrastructure dependency that organisations now have to account for when demonstrating that cyber risk is being managed rather than merely documented.
Edge and network devices can also fall outside the normal rhythm of endpoint and server maintenance. Appliances are often long-lived, managed by service providers, deployed across branch locations, or treated as background infrastructure once installed. That can make asset ownership, firmware visibility, and responsibility for remediation less obvious than for centrally managed computing systems.
The Dutch NCSC’s two alerts focus on the same practical outcome: organisations using affected VigorAP or VigorSwitch equipment should move to the fixed releases provided by DrayTek. Until there is evidence of exploitation, the issue remains a serious product-security exposure rather than a confirmed incident, but the potential for administrative takeover places it well above a routine software defect.





