Volmarg · Prison Management System · CVE-2026-71905
**Name of the Vulnerable Software and Affected Versions**
Volmarg Personal Management System (affected versions not specified)
DrayTek VigorAP (affected versions not specified)
**Description**
Volmarg Personal Management System allows authenticated attackers to read arbitrary files via the 'GET /public/get-file/{path}' endpoint. The `path` route parameter is passed to the `file get contents()` function without canonicalization, which is the process of converting a path to its simplest, standard form, allowing the retrieval of sensitive files accessible to the PHP-FPM worker process.
DrayTek VigorAP models contain a command injection flaw in the `ExportSettings()` function. Insufficient filtering of the `backupkey`, `backuptype`, and `realtime` fields allows a remote attacker with administrative credentials to execute arbitrary commands with root privileges.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.