Draytek critical firmware update / remote code execution vulnerability, alert notice

Soldato
Joined
19 Jun 2009
Posts
4,027
Just a heads up, Draytek have released a critical firmware update for a number of their routers, it relates to remote code execution. I have only discovered this today as the firmware for my 2860 was only released yesterday.

If you own a Draytek router it's worth reading the following link.


Routers affected

Affected ModelFixed Firmware Version
Vigor39104.3.1.1
Vigor3220 Series3.9.7.2
Vigor2962 Series4.3.1.1
Vigor2952 / 2952P3.9.7.2
Vigor2927 Series4.4.0
Vigor2927 LTE Series4.4.0
Vigor2926 Series3.9.8.1
Vigor2926 LTE Series3.9.8.1
Vigor2925 Series3.9.2
Vigor2925 LTE Series3.9.2
Vigor2915 Series4.3.3.2
Vigor29123.8.15
Vigor2866 Series4.4.0
Vigor2866 LTE Series4.4.0
Vigor2865 Series4.4.0
Vigor2865 LTE Series4.4.0
Vigor2862 Series3.9.8.1
Vigor2862 LTE Series3.9.8.1
Vigor2860 Series3.9.2
Vigor2860 LTE Series3.9.2
Vigor28323.9.6.1
Vigor2766 Series4.4.2
Vigor2765 Series4.4.2
Vigor2762 Series3.9.6.4
Vigor2760 Series3.8.9.6
Vigor2620 LTE Series3.9.8.1
VigorLTE 200n3.9.8.1
Vigor2135 Series4.4.2
Vigor2133 Series3.9.6.4
Vigor1000B4.3.1.1
Vigor1664.2.4
Vigor1654.2.4
 
Thanks for the heads up. I'm pretty sure I'm on their mailing list, but haven't seen anything about this. It even affects SSL VPNs - nasty!

I'm on the Draytek mailing list also, yet never received anything either.

Yes the following is also included in the Draytek 2860 firmware.

Improve the OpenSSL security (CVE-2022-0778)
 
Back
Top Bottom