Your Router Is a Loaded Gun: The CVEs That Should Worry Every UK Small Business This Week
The vulnerability data published in the last 24 hours contains two items that belong at the top of any UK small business security briefing. Not because of how they score on a spreadsheet. Because of what they actually do.
Pre-authentication. Remote code execution. Root privileges. These are not edge cases. These are the conditions that make network hardware a direct entry point into your business.
The Two Vulnerabilities That Matter This Week
CVE-2026-71921: DrayTek VigorSwitch pre-authentication command injection
Multiple DrayTek VigorSwitch models contain a command injection flaw in the setget.cgi interface. The vulnerability exists because the pass field is not properly filtered before being passed to command execution. A remote attacker can send crafted input, execute arbitrary commands, and do so with root privileges. No credentials required.
DrayTek hardware is common in UK small and medium business networks. These are not obscure enterprise devices. They are the switches sitting in your comms cabinet, your server room, your back office. If your VigorSwitch is reachable from the internet and running vulnerable firmware, it is exposed right now.
The CVSS score is 9.8. That is not a rounding error.
CVE-2026-71933: DrayTek VigorSwitch unauthorised operation via syslog functions
A companion flaw in the same hardware family. Missing authorisation checks across multiple syslog functions allow a remote attacker to modify device configuration, restart services, save startup configuration, and clear logs. No authentication required.
The log-clearing capability is particularly relevant. An attacker who can erase your switch logs can remove evidence of their own activity. This is not just a configuration risk. It is a forensic risk.
CVE-2026-76071: Netis NC63 firmware stack-based buffer overflow
Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow in the web interface. The vulnerability is in how the device handles the destHost parameter. The Boa web server runs the CGI environment as root, so successful exploitation achieves remote code execution as root without any authentication.
The vendor was contacted before public disclosure and did not respond. The exploit has been publicly disclosed. That means it is available to anyone who wants it, including the kind of automated scanning operations that probe small business networks continuously.
Why This Matters for UK Small Businesses Specifically
The instinct in most small businesses is to treat network hardware as infrastructure: plug it in, configure it once, leave it alone. That instinct is understandable. It is also the reason attackers find unpatched routers and switches sitting at the edge of business networks months or years after patches are available.
DrayTek has a significant UK customer base. VigorSwitch devices appear in accountancy practices, legal firms, healthcare providers, estate agents, and the kind of professional services businesses that hold client data subject to UK GDPR. A device compromise is not just a network problem. It is a data protection incident with ICO notification implications.
Netis NC63 hardware tends to appear in smaller deployments: home offices, small retail environments, businesses that bought a cheap router and never thought about it again. The public availability of a working exploit for this device changes the risk calculation immediately.
The pattern this week is consistent: network hardware sitting at the edge of small business environments, internet-exposed, running outdated firmware, with no monitoring in place to detect when something has changed.
The Oracle WebLogic KEV Entry Is Also Worth Noting
CISA added CVE-2026-21962 to its Known Exploited Vulnerabilities catalogue on 24 August. This affects Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in, allowing unauthorised creation, deletion, or modification of critical data.
Most UK small businesses do not run Oracle WebLogic directly. But the supply chain question is worth asking: does your ERP system, your accounting software, or any cloud service you rely on run Oracle middleware? If you do not know the answer, your IT provider or MSP should. Ask them.
The KEV designation means CISA has confirmed active exploitation. This is not a theoretical risk with a future patch window. It is being used against real targets right now.
Why This Gives You an Edge
Most small businesses do not have a process for tracking vulnerability disclosures. Most do not know which firmware version their network hardware is running. Most have never checked whether their routerβs web interface is accessible from the internet.
The businesses that do have these processes in place are measurably harder to compromise. Not because they have more expensive kit. Because they know what they have and they keep it updated.
If you can tell a client, a procurement team, or an insurer that your network hardware inventory is documented, firmware is reviewed on a defined schedule, and internet-facing management interfaces are disabled or restricted by IP, you are describing security hygiene that most of your competitors cannot claim.
Cyber Essentials certification requires you to control what is internet-facing and keep software up to date. The firmware on your network switches counts. If you are working toward CE or CE+, this weekβs disclosures are a direct test of whether your controls are real or theoretical.
Making the Business Case
Three points worth raising with whoever controls the budget:
The cost of compromise is higher than the cost of patching. A ransomware incident or data breach triggered through an unpatched network device will cost more in recovery, lost time, and potential ICO enforcement than any firmware update or hardware replacement. The comparison is not close.
Insurance is increasingly asking about network hardware. Cyber insurers are tightening their questionnaires. Known vulnerabilities in internet-facing devices are a coverage risk. Some policies exclude incidents where a patch was available and not applied. Check your policy wording.
Your MSP should be doing this for you. If you pay for managed IT support and nobody has mentioned CVE-2026-71921 or reviewed your DrayTek firmware this week, that is a conversation worth having. Managed service means managed, not just reactive support when something breaks.
What to Do Before the End of the Week
1. Identify your network hardware. Make a list of every router, switch, and wireless access point on your network. Include the make, model, and current firmware version. If you do not know this, your IT provider should be able to tell you within the hour.
2. Check whether your hardware is affected. DrayTek VigorSwitch: check the DrayTek UK security advisories for the specific models covered by CVE-2026-71921 and CVE-2026-71933. Netis NC63: if you have one, assume it is vulnerable until proven otherwise. The vendor has not responded to disclosure.
3. Apply available firmware updates. DrayTek publishes firmware updates through its UK support portal. For Netis NC63 with no vendor response and a public exploit, assess whether the device should be replaced entirely. A consumer-grade router with a CVSS 9.8 pre-auth RCE flaw and an unresponsive vendor is not a device worth keeping in a business environment.
4. Disable remote management interfaces where not required. If your router or switch has a web management interface accessible from the internet and you do not actively need remote access to it, disable external access. This removes a significant portion of the attack surface immediately.
5. Check your Oracle software dependencies. Ask your IT provider or software vendors whether any of your business systems use Oracle HTTP Server or Oracle WebLogic. If they do, confirm that CVE-2026-21962 has been addressed.
If your MSP cannot answer questions 1 through 5 within 24 hours, that is the real problem to fix.
Before you go: follow the show wherever you listen, leave a rating or review, drop a comment with your thoughts, and share this episode with someone running a small business who could use a straight answer on what actually matters this week.