Thursday, March 23, 2023
  • Events
  • Interviews
  • Jobs
  • Opinion
  • Whitepapers
  • Podcasts
  • Web Hosting Directory
  • Login
  • Register
Cloud7 News
  • Cloud Computing
  • Web Hosting
  • Data Center
  • Linux
  • Cybersecurity
  • More
    • Software
    • Network/Internet
    • Hardware
    • Artificial Intelligence
    • Windows
    • Policy/Legislation
    • Blockchain
    • Troubleshooting
    • How-Tos
    • Articles
No Result
View All Result
Cloud7 News
  • Cloud Computing
  • Web Hosting
  • Data Center
  • Linux
  • Cybersecurity
  • More
    • Software
    • Network/Internet
    • Hardware
    • Artificial Intelligence
    • Windows
    • Policy/Legislation
    • Blockchain
    • Troubleshooting
    • How-Tos
    • Articles
No Result
View All Result
Cloud7 News
No Result
View All Result

Home > Cybersecurity > A critical RCE bug was detected in 29 router models from DrayTek

A critical RCE bug was detected in 29 router models from DrayTek

A new critical remote code execution bug has been discovered in 29 different DrayTek router models. If successfully exploited, it could lead to full device compromise and unauthorized network access.


Hanife Diktas Hanife Diktas
August 5, 2022
3 min read
A critical RCE bug was detected in 29 router models from DrayTek
  • The Trellix Threat Labs Vulnerability Research team has undisclosed an unauthenticated remote code execution bug affecting a total of 29 DrayTek routers.
  • The vulnerability is classified as critical; having a CVSSv3 severity score of 10.0.
  • It could lead an attacker to perform its attack without needing user interaction or credentials and take control of the full device.

The Trellix Threat Labs Vulnerability Research team has discovered an unauthenticated remote code execution bug affecting multiple DrayTek routers. This flaw was affecting 29 of the DrayTek Vigor series of business routers. It enables an attacker controlling entire of the device and access the unauthorized network.

Bug leads taking control of the device

DrayTek is a Taiwanese company that manufactures Small Office and Home Office (SOHO) routers widely embraced in the UK, Vietnam, and Taiwan. Its popularity grew during the pandemic by the trend of work-from-home working options. This popularity increase led Trellix Threat Labs to make a security assessment of one of the DrayTek flagship products, the Vigor 3910. The researchers quickly came upon a pre-authentication remote code execution vulnerability, affecting 28 other models that share the same codebase, along with Vigor 3910 model.

The discovery filed under CVE-2022-32548, having a CVSS v3 severity score of 10.0, is classified as critical. An attacker could take advantage of this bug to perform its attack without needing user interaction or credentials. The research team stated that an attack can be performed within the LAN in the default device configuration. It is also possible to exploit it via the internet if the device is configured to be internet-facing. The outcomes of the attack can be a leak of sensitive data, access to internal resources located on the LAN, spying on DNS requests, hosting malicious data, etc.

The affected DrayTek routers and versions by the CVE-2022-32548 vulnerability are;

  • Vigor3910 < 4.3.1.1
  • Vigor1000B < 4.3.1.1
  • Vigor2962 Series < 4.3.1.1
  • Vigor2927 Series < 4.4.0
  • Vigor2927 LTE Series < 4.4.0
  • Vigor2915 Series < 4.3.3.2
  • Vigor2952 / 2952P < 3.9.7.2
  • Vigor3220 Series < 3.9.7.2
  • Vigor2926 Series < 3.9.8.1
  • Vigor2926 LTE Series < 3.9.8.1
  • Vigor2862 Series < 3.9.8.1
  • Vigor2862 LTE Series < 3.9.8.1
  • Vigor2620 LTE Series < 3.9.8.1
  • VigorLTE 200n < 3.9.8.1
  • Vigor2133 Series < 3.9.6.4
  • Vigor2762 Series < 3.9.6.4
  • Vigor167 < 5.1.1Vigor130 < 3.8.5
  • VigorNIC 132 < 3.8.5
  • Vigor165 < 4.2.4
  • Vigor166 < 4.2.4
  • Vigor2135 Series < 4.4.2
  • Vigor2765 Series < 4.4.2
  • Vigor2766 Series < 4.4.2
  • Vigor2832 < 3.9.6
  • Vigor2865 Series < 4.4.0
  • Vigor2865 LTE Series < 4.4.0
  • Vigor2866 Series < 4.4.0
  • Vigor2866 LTE Series < 4.4.0

During the assessment, the researchers found over 200k devices that have vulnerable firmware are currently exposed on the internet and would require no user interaction to be exploited. Many more devices where the affected service is not exposed externally are still vulnerable to a one-click attack from the LAN. The Taiwanese company reacted to the discovery quickly and released a patch in less than 30 days.

    See more Cybersecurity News

    A comprehensive guide to understanding Cybersecurity: What is Cybersecurity?


    Tags: DrayTekTrellixVulnerability
    Hanife Diktas

    Hanife Diktas

    Hanife Diktas is a news editor at Cloud7 News. Hanife started her career in the manufacturing sector in the marketing and sales department. Hanife worked in industrial equipment, renewable energy, and technology sectors. Hanife Diktas did her bachelor's degree in business administration and completed a master's degree in management at Yeditepe University in Istanbul, Turkey. Hanife is a Linux user, and she also contributed to AlmaLinux OS at the beginning of the project. Hanife focuses on web hosting, cloud computing, data centers, cybersecurity, Linux OS, and virtualization technologies. Hanife enjoys creating content and shooting videos covering these topics.

    Leave a Reply Cancel reply

    Your email address will not be published. Required fields are marked *

    I agree to the Terms & Conditions and Privacy Policy.

    Next Post
    Google Chrome 104 is released with 27 security issues fixes

    Google Chrome 104 is released with 27 security fixes

    Related News

    CISA aims to identify vulnerabilities that attract ransomware

    CISA aims to identify vulnerabilities that attract ransomware

    March 22, 2023 2:10 pm
    7 best cybersecurity schools

    7 best cyber security schools

    March 21, 2023 9:00 pm
    Akamai researchers warn about the new HinataBot botnet

    Akamai researchers warn about the new HinataBot botnet

    March 20, 2023 6:10 pm
    7 biggest data breaches in the history of the internet

    7 biggest data breaches in the history of the internet

    March 16, 2023 10:55 pm
    Get free daily newsletters from Cloud7 News Get the Cloud7 Newsletter
    Select list(s):

    Check your inbox or spam folder to confirm your subscription.

    By subscribing, you agree to our
    Copyright Policy and Privacy Policy

    Get the free newsletter

    Subscribe to receive the latest IT business updates straight to your inbox.

    Select list(s):

    Check your inbox or spam folder to confirm your subscription.

    Recent News

    • How to change system language on Windows 11
    • How to create and manage menus in WordPress
    • Interview: Tim Mackey, head of supply chain risk strategy of Synopsys
    • 7 richest domains and the reasons why
    • CISA aims to identify vulnerabilities that attract ransomware

    Cloud7 News
    Cloud7 is a news source that publishes the latest news, reviews, comparisons, opinions, and exclusive interviews to help tech users of high-experience levels in the IT industry.

    EXPLORE

    • Web Hosting
    • Cloud Computing
    • Data Center
    • Cybersecurity
    • Linux
    • Network/Internet
    • Software
    • Hardware
    • Artificial Intelligence
    • How-Tos
    • Troubleshooting

    RESOURCES

    • Events
    • Interviews
    • Jobs
    • Opinion
    • Whitepapers
    • Podcasts
    • Web Hosting Directory

    Get the Cloud7 Newsletter

    Get FREE daily newsletters from Cloud7 delivering the latest news and reviews.

    • About Us
    • Privacy & Policy
    • Copyright Policy
    • Contact

    © 2023, Cloud7 News. All rights reserved.

    No Result
    View All Result
    • Cloud Computing
    • Web Hosting
    • Data Center
    • Linux
    • Cybersecurity
    • More
      • Software
      • Network/Internet
      • Hardware
      • Artificial Intelligence
      • Windows
      • Policy/Legislation
      • Blockchain
      • Troubleshooting
      • How-Tos
      • Articles
    • Events
    • Interviews
    • Jobs
    • Opinion
    • Whitepapers
    • Podcasts
    • Web Hosting Directory

    © 2023, Cloud7 News. All rights reserved.

    Welcome Back!

    Sign In with Facebook
    Sign In with Google
    Sign In with Linked In
    OR

    Login to your account below

    Forgotten Password? Sign Up

    Create New Account!

    Sign Up with Facebook
    Sign Up with Google
    Sign Up with Linked In
    OR

    Fill the forms below to register

    *By registering into our website, you agree to the Terms & Conditions and Privacy Policy.
    All fields are required. Log In

    Retrieve your password

    Please enter your username or email address to reset your password.

    Log In

    Add New Playlist

    This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.