None
EN
DrayTek warns of remote code execution bug in Vigor routers
[]
BleepingComputer
Networking hardware maker DrayTek released an advisory to warn about a security vulnerability in several Vigor router models that could allow remote, unauthenticated actors to execute perform arbitrary code.
"Successful exploitation may cause memory corruption and a system crash, with the potential in certain circumstances could allow remote code execution."
DrayTek noted that WAN exposure can be reduced by disabling remote WebUI/SSL VPN access or restricting it with ACLs/VLANs.
LTE & 5G), Vigor2927 Series (incl.
LTE & 5G) → 4.5.1 or laterVigor2915 Series → 4.4.6.1 or laterVigor2862/2926 Series (incl.