Jump to content

Recommended Posts

Posted

https://www.ispreview.co.uk/index.php/2025/03/broadband-isps-report-uk-connectivity-problems-with-vulnerable-draytek-routers.html

 

https://www.resetera.com/threads/psa-issue-with-draytek-routers-in-the-uk.1142901/

 

This looks like an attack on unpatched devices utilising the 10/10 CVE that was released last year. 

 

Or it may be a whole new issue. 

 

Reports seem to be mainly centred around the UK and Vietnam.

 

Not an issue for me, but it might be for others!

Posted

Yes its quite a nasty one if you've left remote management open to the world. Easily fixable, but perhaps not if you've got thousands of them out there.

 

We've already seen numerous of our customers who used Drayteks on their own suffer from this thinking it was a line issue when actually it was their router (not supplied by us btw).

 

A rough fix is

 

1. Take router offline

2. If you must allow remote access to the web interface then lock this down to specific hosts.

3. I'd recommend moving the ports for remote access to something different that default. e.g. HTTPS move from port 443 to say 444.

4. Upgrade the firmware to the latest version.

5. Reconnect and your router should then be fixed and further secured.

 

Dave

 

  • Thanks 2

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...