DrayTek is working to release a new security update for its router firmware, following customer reports regarding the recent zero-day. This vulnerability allowed hackers to change the router's DNS settings, enabling them to redirect unsuspecting users to other malicious websites.

DrayTek's new announcement states: "We are aware of the security gap in our routers. In some cases, it may be possible for an attacker to intercept or create an administrator login and change the settings of your device. Several of the reports we received were seriously investigated and it appears that there have indeed been incidents of changed DNS by malicious users. A firmware update is definitely necessary to combat the problem and we are in the process of creating and releasing new software. You should install it as soon as possible. We also recommend that you only use secure (TLS1.2) connections for web admin (for local administrator) and disable remote access if it is not necessary."
It is believed that there are approximately 800,000 DrayTek devices online without knowing how many of them are vulnerable.
Researcher Nionet Sion Lloyd argued that because DNS is an underlying protocol that directs traffic on the internet, it is often overlooked by administrators in security and monitoring matters, and therefore is considered a primary target for hackers.
The models affected are: Vigor2120; 2133; 2760D; 2762; 2832; 2860; 2862; 2862B; 2912; 2925; 2926; 2952; 3200; 3220; BX2000; 2830nv2; 2830; 2850; and 2920.
Finally, DrayTek urged users to check their DNS settings and correct them if they have been changed or restore them from a backup file, until the new updated version is released.
