DrayOS Router Flaw Allows Remote Code Execution by Attackers
A critical vulnerability affecting DrayOS routers has been identified, allowing unauthenticated attackers to execute code remotely.
A critical vulnerability affecting DrayOS routers has been identified, allowing unauthenticated attackers to execute code remotely.
Discovered on Tue, Jul 22, 2025, by Pierre-Yves Maes of ChapsVision, the vulnerability originates from the use of an uninitialized variable in the Web User Interface (WebUI).
Specially crafted HTTP or HTTPS requests to the WebUI can trigger memory corruption, potentially crashing the device or enabling remote code execution in specific scenarios.
This vulnerability does not require valid credentials and can be exploited by any attacker with network access to the router’s WebUI.
Typically, routers are shielded from wide-area-network (WAN) threats if WebUI and SSL VPN services are disabled or protected via Access Control Lists (ACLs). However, local attackers remain at risk.
A critical vulnerability affecting DrayOS routers has been identified, allowing unauthenticated attackers to execute code remotely.
CVE ID Vulnerability Impact Exploit Prerequisites
CVE-2025-10547 Use of uninitialized variable in WebUI logic Remote code execution Unauthenticated HTTP/HTTPS to WebUI
On some models, LAN-side VLANs and ACLs provide additional control over WebUI access. In the absence of these controls, sending a maliciously crafted request is sufficient to exploit the vulnerability.
Memory corruption leading to device instability or crash Potential execution of arbitrary code under the system’s privilege context
To mitigate this risk, DrayTek has released firmware updates that address the uninitialized variable usage. Administrators are advised to upgrade affected models to the versions listed below at the earliest opportunity.
Affected models include the Vigor1000B, Vigor2962, Vigor3910, Vigor3912, Vigor2135, and various models within the Vigor276x, Vigor286x, Vigor291x, Vigor292x, and Vigor295x series, among others.
Routers remain secure against external attackers when WebUI and SSL VPN are disabled or protected by ACLs. However, local network access is sufficient to exploit the flaw if firmware remains outdated. Apply the updates immediately to ensure full protection.
Based on reporting by GBHackers.
