Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

Draytek urgent security patch - 10/10 CVE + more


Recommended Posts

Posted

If you are running a Draytek router they have released a patch to plug a hole which was found to aid a botnet.

 

If you are looking for the patch make sure and use Draytek.co.uk as I think .com doesnt have the required BT firmware for VDSL.

 

https://www.draytek.co.uk/support/downloads

 

A new report by Forescout Research has identified 14 new security vulnerabilities in 24 models of DrayTek‘s popular Vigor routers, which is a familiar name in the UK broadband ISP world. One of the vulnerabilities even has a Common Vulnerability Score (CVSS) of 10 out of 10 and over 704,000 routers were found exposed online in 168 countries.

 

The report (here) notes that approximately 785,000 DrayTek devices are operating Wi-Fi networks in the wild (over 425,000 of those are in Europe – with 36% in the UK). According to the vendor, DrayTek’s Vigor Web UI “should only be accessible from a local network for security reasons“, but the study “found over 704,000 DrayTek routers that have their UI exposed to the Internet” (most of these are used by businesses and some advanced home users).

 

draytek.png

 

Source: https://www.ispreview.co.uk/index.php/2024/10/serious-security-vulnerabilities-exposed-in-704000-draytek-routers.html

Report: https://www.forescout.com/resources/draybreak-draytek-research/

  • Thanks 2

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...