None
EN
DrayTek warns Vigor routers may have serious security flaws - here's what we know
['Sead Fadilpašić', 'Social Links Navigation']
Latest from TechRadar
In a security advisory, DrayTek said it discovered an “uninitialized variables in the firmware” vulnerability in DrayOS (the OS powering Vigor routers) which, if exploited, could result in memory corruption or system crashes.
There is also “potential in certain circumstances” to use the bug for remote code execution, as well.
DrayTek says the bug only affects routers that have remote access to the WebUI and SSL VPN services enabled, as well as those whose Access Control Lists (ACLs) are misconfigured.
“Nevertheless, an attacker with access to the local network could still exploit the vulnerability via the WebUI,” the advisory explains.
“Local access to the WebUI can be controlled on some models using LAN side VLANs and ACLs.