A critical remote command execution vulnerability affecting DrayTek devices has been added to CISA’s Known Exploited Vulnerabilities catalog, underscoring the urgency of applying patches. This flaw allows attackers to remotely execute arbitrary commands, seriously endangering the affected systems. Given the ongoing exploitation activity, it is crucial to perform an immediate update to protect against potential attacks.
| Product | DrayTek Vigor |
| Date | 2024-10-03 15:44:01 |
| Information |
|
Technical Summary
A critical unauthenticated remote code execution vulnerability affecting DrayTek Vigor3900, Vigor2960, and Vigor300B devices (versions prior to 1.5.1).
Recommendations
Immediate firmware update: Users are strongly advised to check their firmware versions and update them to the latest version available in the table below. Before proceeding, it is necessary to back up current configurations using the
.ALLfile to avoid loss of settings. If updating from older versions, consult the release notes for specific instructions.Disable remote access: If remote access is not required, it is advisable to disable it. Users should also implement access control lists and two-factor authentication where possible. Additionally, temporarily disable SSL VPN if the device is not running the updated firmware.
Change the router administration password: It is recommended to update the router administration password as an additional security measure.
Protect your organisation with Threat Intelligence and Digital Risk Protection.
Choose ISGroup for a practical, tailored engagement:
- A focused assessment of your environment and requirements
- Clear findings with a prioritised, actionable roadmap
- Direct support from experienced specialists through remediation and implementation
