DrayTek has released security updates for various router models to fix 14 vulnerabilities.

The vulnerabilities were discovered by Forescout Research – Vedere Labs and affect both supported models and routers that have reached the so-called end-of-life. However, due to the severity of some of the vulnerabilities, DrayTek has released fixes for both categories of routers.
According to the researchers, approximately 785,000 DrayTek routers may be vulnerable and over 704,500 have their web interface exposed to the internet.
See also: Beware! Hackers exploit critical Zimbra vulnerability
Nearly half of these devices are located in the United States, but Shodan results also show significant numbers in the United Kingdom, Vietnam, the Netherlands, and Australia.
DrayTek router: Vulnerabilities
Most of the vulnerabilities are medium-severity buffer overflow and cross-site scripting issues. However, there are five more serious bugs that pose significant risks to devices:
FSCT-2024-0006 (CVSS Score: 10.0): The most severe vulnerability discovered. It is a buffer overflow in the “GetCGI()” function, which is responsible for handling HTTP request data. The vulnerability can lead to a denial of service (DoS) attack or remote code execution (RCE).
FSCT-2024-0007 (CVSS Score: 9.1): A Command Injection vulnerability in OS Communication. The “recvCmd” binary used for communication between host and guest operating systems is vulnerable to attacks , potentially allowing VM escape.
FSCT-2024-0014 (CVSS Score: 7.6): The web server backend uses a static string to generate a pseudo-random number generator (PRNG) in OpenSSL for TLS connections. This could lead to information disclosure and man-in-the-middle (MiTM) attacks.
FSCT-2024-0001 (CVSS Score: 7.5): Using identical administrator credentials across the entire system can lead to a complete system compromise (if attackers obtain these credentials).
FSCT-2024-0002 (CVSS Score: 7.5): An HTML page in the Web UI incorrectly handles input.
So far, there is no evidence or reports that prove active exploitation of these flaws.
The above vulnerabilities affect 24 DrayTek router models, 11 of which are no longer officially supported by the company (end-of-life).
See also: New Bluetooth vulnerability leaks Passkeys during pairing
In the table below you can see the models that are affected:

Users can download the latest firmware for their router from DrayTek's official download portal.
Also, for maximum protection, users are asked to do the following:
- Disable remote access if not needed.
- Using an access control list.
- Implement two-factor authentication.
- Check settings for possible changes or add administrator users or remote access profiles.
- Disable SSL VPN connections over port 443.
- Enable syslog logging to monitor suspicious events.
- Enable automatic refresh on HTTP pages in the browser.
All DrayTek router users should confirm that their device's remote access console is disabled!
By implementing these additional measures, users can further enhance the security of DrayTek routers and protect their networks from potential threats. It is also important to stay up to date on any new vulnerabilities or updates released by DrayTek or other manufacturers.
See also: Hackers exploit critical SolarWinds Serv-U vulnerability
Additionally, education plays a critical role in maintaining network security. It is essential to educate ourselves on the importance of strong passwords, phishing , and other common tactics used by attackers to gain access to networks. Regular education and awareness programs can help prevent potential security breaches caused by human error.
By adopting a proactive approach to cybersecurity and taking the necessary protective measures, we can create a safer online environment for ourselves and others.
Source: www.bleepingcomputer.com
