Jump to content


Photo

Draytek router vulnerabilities - You need to update


  • Please log in to reply
3 replies to this topic

#1 WanWizard

  • PLi® Core member
  • 70,089 posts

+1,794
Excellent

Posted Yesterday, 11:21

We are writing to inform you about critical security vulnerabilities discovered in several DrayTek products on June 20, 2024. These vulnerabilities include Cross-Site Scripting, Denial of Service, and Remote Code Execution issues. We have addressed these concerns and released firmware updates to enhance security.

Vulnerability Details:

  • Published Date: 2024/10/4
  • CVE IDs: CVE-2024-41583 to CVE-2024-41596
  • Types: Cross-Site Scripting, Denial of Service, Remote Code Execution

CVE number  CVSS CVE-2024-41583  4.7 CVE-2024-41584  4.7 CVE-2024-41585  6.8 CVE-2024-41586  8 CVE-2024-41587  5.4 CVE-2024-41588  8 CVE-2024-41589  8.8 CVE-2024-41590  8 CVE-2024-41591  6.1 CVE-2024-41592  8 CVE-2024-41593  9.8 CVE-2024-41594  7.5 CVE-2024-41595  8 CVE-2024-41596  8

Urgent Action Required:

1. Upgrade your firmware immediately to the version listed below for your device.
2. Before upgrading: 

  • Back up your current configuration (System Maintenance > Config Backup).
  • Use the ".ALL" file for upgrading to preserve your settings.
  • If upgrading from an older version, review the release notes for specific instructions.

3. If remote access is enabled: 

  • Disable it unless absolutely necessary.
  • Use an access control list (ACL) and enable 2FA if possible.
  • For unpatched routers, disable both remote access (admin) and SSL VPN.
  • Note: ACL doesn't apply to SSL VPN (Port 443), so temporarily disable SSL VPN until upgraded.

Affected Products and Fixed Firmware Versions: 

  • Vigor165 - 4.2.7
  • Vigor166 - 4.2.7 
  • Vigor1000B - 4.3.2.8 4.4.3.2* 
  • Vigor2133 - 3.9.9 
  • Vigor2135 - 4.4.5.3 
  • Vigor2620 LTE - 3.9.8.9 
  • Vigor2762 - 3.9.9 
  • Vigor2763 - 4.4.5.3 
  • Vigor2765 - 4.4.5.3 
  • Vigor2766 - 4.4.5.3 
  • Vigor2832 - 3.9.9 
  • Vigor2860 / 2860 LTE - 3.9.8 
  • Vigor2862 / 2862 LTE - 3.9.9.5 
  • Vigor2865 / 2865 LTE - 4.4.5.2 
  • Vigor2866 / 2866 LTE - 4.4.5.2 
  • Vigor2915 - 4.4.3.2 
  • Vigor2925 / 2925 LTE - 3.9.8 
  • Vigor2926 / 2926 LTE - 3.9.9.5 
  • Vigor2927 / 2927 LTE / 2927L-5G - 4.4.5.5 
  • Vigor2952 / 2952 LTE - 3.9.8.2 
  • Vigor2962 - 4.3.2.8 4.4.3.1 
  • Vigor3220n - 3.9.8.2 
  • Vigor3910 - 4.3.2.8 4.4.3.1 
  • Vigor3912 - 4.3.6.1 

*Firmware unreleased

Additional Security Measures: 

  • Regularly check for and apply firmware updates.
  • Implement strong, unique passwords for all accounts.
  • Enable and configure firewall settings appropriately.
  • Monitor your network for any suspicious activities.

Next Steps:If you haven't already, please update your device immediately. For products with unreleased firmware (marked with *), please stay vigilant for our upcoming announcements and update promptly once available.

Should you need any assistance with the update process or have security-related inquiries, please don't hesitate to contact our Technical Support team.

We appreciate your prompt attention to this critical security matter and thank you for your continued trust in DrayTek products.

Best regards, DrayTek Security Team


Currently in use: VU+ Duo 4K (2xFBC S2), VU+ Solo 4K (1xFBC S2), uClan Usytm 4K Ultimate (S2+T2), Octagon SF8008 (S2+T2), Zgemma H9.2H (S2+T2)

Due to my bad health, I will not be very active at times and may be slow to respond. I will not read the forum or PM on a regular basis.

Many answers to your question can be found in our new and improved wiki.


Re: Draytek router vulnerabilities - You need to update #2 Jork

  • Senior Member
  • 783 posts

+13
Neutral

Posted Yesterday, 19:51

Een kwetsbaar zaakje in herhaling daar. Twee jaar geleden ook al.

https://exa.net.uk/k...-vulnerability/.

Re: Draytek router vulnerabilities - You need to update #3 Tech

  • Forum Moderator
    PLi® Core member
  • 14,880 posts

+485
Excellent

Posted Yesterday, 20:04

Een kwetsbaar zaakje in herhaling daar. Twee jaar geleden ook al.

https://exa.net.uk/k...-vulnerability/.

Toen betrof het maar drie routers, ditmaal is de lijst aanmerkelijk langer, ook mijn router staat ertussen en heb direct de boel ge-update naar de laatste versie.


Aan de rand van de afgrond is een stap voorwaarts niet altijd vooruitgang....

On the edge of the abyss, a step forward is not always progress....

Hardware: 2x Daily used Vu+ Ultimo 4K - Vu+ Duo 4K SE and a lot more.... - VisioSat BiBigsat - Jultec Unicable Multiswitch 4 positions: 19.2/23.5/28.2 East - Diseqc motorized flatdish antenna

Software : HomeBuild OpenPLi Develop and Scarthgap builds, local cards driven by OsCam

Press the Geplaatste afbeelding button on the buttom right of this message ;)

Have you tried our wiki yet? Many answers can be found in our OpenPLi wiki


Re: Draytek router vulnerabilities - You need to update #4 WanWizard

  • PLi® Core member
  • 70,089 posts

+1,794
Excellent

Posted Yesterday, 21:44

Het had ook wel iets sneller gemogen, dit is van 4 oktober, kreeg deze mail vanmorgen pas van de importeur.


Currently in use: VU+ Duo 4K (2xFBC S2), VU+ Solo 4K (1xFBC S2), uClan Usytm 4K Ultimate (S2+T2), Octagon SF8008 (S2+T2), Zgemma H9.2H (S2+T2)

Due to my bad health, I will not be very active at times and may be slow to respond. I will not read the forum or PM on a regular basis.

Many answers to your question can be found in our new and improved wiki.



1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users