CVE Alert: CVE-2022-50994 - DrayTek - Vigor 2960 - RedPacket Security

DrayTek Vigor 2960 firmware versions prior to 1.5.1.4 contain an OS command injection vulnerability in the CGI login handler that allows unauthenticated

RedPacket Security

Is there a way to remove the default admin account on a #DrayTek switch from the web interface? As best as I can tell you can only make it 'view only'.

And whoever thought the management rules list shouldn't differentiate enabled/disabled.......

And you cannot aggregate "normal" ports with "fiber" ports

A tiny glitch in DrayTek Vigor routers could let hackers seize control remotely. It's a stark reminder that even the smallest bug can open the door to big risks. Have you updated your firmware yet?

https://thedefendopsdiaries.com/cve-2025-10547-critical-remote-code-execution-vulnerability-in-draytek-vigor-routers/

#cve202510547
#draytek
#remotecodeexecution
#routersecurity
#firmwareupdate

CVE-2025-10547: Critical Remote Code Execution Vulnerability in DrayTek Vigor Routers

Explore the critical CVE-2025-10547 vulnerability in DrayTek Vigor routers, its risks, mitigation steps, and industry-wide security lessons.

The DefendOps Diaries

New blog post: https://blog.mei-home.net/posts/snmp-exporter/

A short one this time, about my setup for getting some SNMP data provided by my DrayTek VDSL modem into Prometheus.

#HomeLab #Blog #Prometheus #DrayTek

Gathering SNMP Metrics with the SNMP Exporter

Gathering metrics from a DrayTek VDSL modem

ln --help

Critical vulnerabilities have been exposed in DrayTek routers, putting devices at risk. Make sure your network is secure by staying updated on the latest cybersecurity threats.

#CyberSecurity #DrayTek #Vulnerability https://zurl.co/E1PhU

Critical Vulnerabilities in DrayTek Routers Exposes Devices to RCE Attack

A series of critical vulnerabilities in DrayTek Vigor routers—widely deployed in small office/home office (SOHO) environments.

Cyber Security News
Warnung vor Angriffen auf neue SAP-Netweaver-Lücke, Chrome und Draytek-Router

Die US-amerikanische IT-Sicherheitsbehörde CISA warnt vor Angriffen auf eine neue SAP-Netweaver-Lücke sowie auf Chrome und Draytek-Router.

heise online

#BSI: #DrayTek #Vigor: Mehrere Schwachstellen

Es bestehen mehrere Schwachstellen in DrayTek Vigor Routern. Ein Angreifer kann diese ausnutzen, um Daten zu stehlen, Sicherheitsmaßnahmen zu umgehen, das Gerät zum Absturz zu bringen und Schadcode auszuführen.

https://wid.cert-bund.de/portal/wid/buergercert/details?uuid=735d2ad1-6722-431e-8e5d-3c673ef54837

Warn- und Informationsdienst

Jemand hier Ahnung von Mesh-Wifi mit #Draytek Geräten? Konkret ein 2865Lac und 2x AP903 (wired uplink).

Mein Mesh funzt, aber die APs nehmen partout die Configsync vom Router nicht an (außer SSID1).

Jemand eine Idee warum?

🚨 Following reports of widespread DrayTek router reboots, GreyNoise is bringing awareness to in-the-wild activity against multiple known vulnerabilities in DrayTek devices. Read the analysis ⬇️

https://www.greynoise.io/blog/in-the-wild-activity-against-draytek-routers

#GreyNoise #ThreatIntel #Cybersecurity #DrayTek

Amid Reports of Worldwide Reboots, GreyNoise Observes In-the-Wild Activity Against DrayTek Routers

GreyNoise is bringing awareness to in-the-wild activity against several known vulnerabilities in DrayTek devices CVE-2020-8515, CVE-2021-20123, and CVE-2021-20124.

DrayTek router chaos! 🌐 Wereldwijd internetproblemen. Netwerkbeheerders, controleer je systemen en update je firmware! #TechNews #DrayTek 
https://itinsights.nl/analyses/draytek-router-apocalyps-internet-ploft-volledig-uit/
DrayTek Router Apocalyps: Internet Ploft Volledig Uit!

Wereldwijd ervaren internetproviders en netwerkbeheerders momenteel aanzienlijke uitdagingen met DrayTek routers, wat wijst op een grootschalige connectiviteitsproblematiek die begon in het weekend.

IT INSIGHTS