Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

DrayOS Router Flaw Allows Remote Code Execution by Attackers

A critical vulnerability affecting DrayOS routers has been identified, allowing unauthenticated attackers to execute code remotely.

A critical vulnerability affecting DrayOS routers has been identified, allowing unauthenticated attackers to execute code remotely.

Discovered on Tue, Jul 22, 2025, by Pierre-Yves Maes of ChapsVision, the vulnerability originates from the use of an uninitialized variable in the Web User Interface (WebUI).

Specially crafted HTTP or HTTPS requests to the WebUI can trigger memory corruption, potentially crashing the device or enabling remote code execution in specific scenarios.

This vulnerability does not require valid credentials and can be exploited by any attacker with network access to the router’s WebUI.

Typically, routers are shielded from wide-area-network (WAN) threats if WebUI and SSL VPN services are disabled or protected via Access Control Lists (ACLs). However, local attackers remain at risk.

A critical vulnerability affecting DrayOS routers has been identified, allowing unauthenticated attackers to execute code remotely.
Eleanor Tate · Thehackingpost

CVE ID Vulnerability Impact Exploit Prerequisites

CVE-2025-10547 Use of uninitialized variable in WebUI logic Remote code execution Unauthenticated HTTP/HTTPS to WebUI

On some models, LAN-side VLANs and ACLs provide additional control over WebUI access. In the absence of these controls, sending a maliciously crafted request is sufficient to exploit the vulnerability.

Memory corruption leading to device instability or crash Potential execution of arbitrary code under the system’s privilege context

Advertisement

To mitigate this risk, DrayTek has released firmware updates that address the uninitialized variable usage. Administrators are advised to upgrade affected models to the versions listed below at the earliest opportunity.

Affected models include the Vigor1000B, Vigor2962, Vigor3910, Vigor3912, Vigor2135, and various models within the Vigor276x, Vigor286x, Vigor291x, Vigor292x, and Vigor295x series, among others.

Routers remain secure against external attackers when WebUI and SSL VPN are disabled or protected by ACLs. However, local network access is sufficient to exploit the flaw if firmware remains outdated. Apply the updates immediately to ensure full protection.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories