Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

DrayOS Routers Vulnerability Let Attackers Execute Malicious Code Remotely

A critical vulnerability has been identified in DrayTek's DrayOS routers, allowing potential unauthorized remote code execution by attackers. This issue, designated as CVE-2025-10547, impacts various Vigor router models, necessitating prompt security…

A critical vulnerability has been identified in DrayTek's DrayOS routers, allowing potential unauthorized remote code execution by attackers. This issue, designated as CVE-2025-10547, impacts various Vigor router models, necessitating prompt security updates from system administrators.

The vulnerability, described in security advisory DSA-2025-005 dated Mon, Oct 2, 2025, is a "Use of Uninitialized Variable" weakness. It can be activated by sending specially crafted HTTP or HTTPS requests to the device's Web User Interface (WebUI), possibly leading to memory corruption and system crashes.

Under certain conditions, this memory corruption may permit remote code execution (RCE) on the affected device. Routers with an internet-exposed WebUI are particularly vulnerable. The flaw was initially detected on Mon, Jul 22, 2025, with public disclosure highlighting the extensive risk due to the widespread use of DrayTek routers in business settings.

DrayTek recommends disabling remote access to the WebUI and SSL VPN services from the WAN as immediate mitigation. Properly configured Access Control Lists (ACLs) can further restrict unauthorized internet access. However, these measures may not fully protect against attacks from within the local network.

A critical vulnerability has been identified in DrayTek's DrayOS routers, allowing potential unauthorized remote code execution by attackers.
Carter Hartwell · Thehackingpost

For additional security, certain models support local access segmentation using VLANs and further ACLs. DrayTek stresses that the only complete resolution to the vulnerability is through upgrading the device firmware to the recommended patched version.

The vulnerability affects a broad spectrum of DrayTek's Vigor router series. Models include the Vigor1000B, Vigor2962, Vigor3910, Vigor3912, Vigor2135, and various models within the Vigor276x, Vigor286x, Vigor291x, Vigor292x, and Vigor295x series, among others.

DrayTek has released specific firmware updates for each affected product line. For instance, Vigor2962 users should upgrade to version 4.4.3.6 or 4.4.5.1, while Vigor2865 Series users need to install version 4.5.1 or later.

Advertisement

The company acknowledges Pierre-Yves MAES from ChapsVision for responsibly disclosing the vulnerability. Users of affected DrayTek products are advised to review the official advisory to ascertain applicable models and minimum firmware versions required for patching.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories