HomeSecurityCritical RCE vulnerability affects 29 DrayTek router models

Critical RCE vulnerability affects 29 DrayTek router models

A critical remote code execution ( RCE ) vulnerability, without authentication, affects 29 models of the DrayTek Vigor series of professional routers, researchers at Trellix have discovered .

See also: Chrome zero-day vulnerability used to infect journalists with spyware

DrayTek

The vulnerability is tracked as CVE-2022-32548 and carries a maximum CVSS v3 severity score of 10.0, categorizing it as critical.

The attacker does not need credentials or user interaction to exploit the vulnerability, with the default device configuration making the attack viable over the Internet and LAN.

Malicious users who exploit this vulnerability could potentially perform the following actions:

full device takeover,

access to information,

creating fertile ground for hidden "man-in-the-middle" attacks,

change DNS settings,

use of routers as DDoS bots or cryptominers,

rotation on devices connected to the compromised network

See also: CISA to organizations: Fix this zero-day vulnerability immediately

DrayTek Vigor devices became very popular during the pandemic. They are extremely affordable products for VPN access in small and medium business networks.

A search on Shodan showed over 700,000 electronic devices, most of which are located in the United Kingdom, Vietnam, the Netherlands, and Australia.

vulnerability

Trellix decided to evaluate the security of one of DrayTek's top models due to its popularity and found that the web management interface suffers from a buffer overflow issue on the login page.

By using a specially crafted credential pair as base64-encoded strings in the login fields, one can trigger the flaw and take control of the device's operating system.

The researchers found that at least 200,000 of the routers detected expose the vulnerable service to the Internet and are therefore easily exploitable without user interaction or other special requirements.

Of the remaining 500,000, many are also believed to be exploitable using one-click attacks, but only over LAN, so the attack surface is smaller.

The vulnerable models are the following:

  • Vigor3910
  • Vigor1000B
  • Vigor2962 Series
  • Vigor2927 Series
  • Vigor2927 LTE Series
  • Vigor2915 Series
  • Vigor2952 / 2952P
  • Vigor3220 Series
  • Vigor2926 Series
  • Vigor2926 LTE Series
  • Vigor2862 Series
  • Vigor2862 LTE Series
  • Vigor2620 LTE Series
  • VigorLTE 200n
  • Vigor2133 Series
  • Vigor2762 Series
  • Vigor167
  • Vigor130
  • VigorNIC 132
  • Vigor165
  • Vigor166
  • Vigor2135 Series
  • Vigor2765 Series
  • Vigor2766 Series
  • Vigor2832
  • Vigor2865 Series
  • Vigor2865 LTE Series
  • Vigor2866 Series
  • Vigor2866 LTE Series

See also: Google fixes serious zero-day vulnerability in Chrome browser

DreyTek quickly released security updates for all the models listed above, so go to the firmware update center and locate the latest version for model .

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS