DrayOS Routers Vulnerability Let Attackers Execute Malicious Code Remotely
A critical vulnerability has been identified in DrayTek's DrayOS routers, allowing potential unauthorized remote code execution by attackers. This issue, designated as CVE-2025-10547, impacts various Vigor router models, necessitating prompt security…
A critical vulnerability has been identified in DrayTek's DrayOS routers, allowing potential unauthorized remote code execution by attackers. This issue, designated as CVE-2025-10547, impacts various Vigor router models, necessitating prompt security updates from system administrators.
The vulnerability, described in security advisory DSA-2025-005 dated Mon, Oct 2, 2025, is a "Use of Uninitialized Variable" weakness. It can be activated by sending specially crafted HTTP or HTTPS requests to the device's Web User Interface (WebUI), possibly leading to memory corruption and system crashes.
Under certain conditions, this memory corruption may permit remote code execution (RCE) on the affected device. Routers with an internet-exposed WebUI are particularly vulnerable. The flaw was initially detected on Mon, Jul 22, 2025, with public disclosure highlighting the extensive risk due to the widespread use of DrayTek routers in business settings.
DrayTek recommends disabling remote access to the WebUI and SSL VPN services from the WAN as immediate mitigation. Properly configured Access Control Lists (ACLs) can further restrict unauthorized internet access. However, these measures may not fully protect against attacks from within the local network.
A critical vulnerability has been identified in DrayTek's DrayOS routers, allowing potential unauthorized remote code execution by attackers.
For additional security, certain models support local access segmentation using VLANs and further ACLs. DrayTek stresses that the only complete resolution to the vulnerability is through upgrading the device firmware to the recommended patched version.
The vulnerability affects a broad spectrum of DrayTek's Vigor router series. Models include the Vigor1000B, Vigor2962, Vigor3910, Vigor3912, Vigor2135, and various models within the Vigor276x, Vigor286x, Vigor291x, Vigor292x, and Vigor295x series, among others.
DrayTek has released specific firmware updates for each affected product line. For instance, Vigor2962 users should upgrade to version 4.4.3.6 or 4.4.5.1, while Vigor2865 Series users need to install version 4.5.1 or later.
The company acknowledges Pierre-Yves MAES from ChapsVision for responsibly disclosing the vulnerability. Users of affected DrayTek products are advised to review the official advisory to ascertain applicable models and minimum firmware versions required for patching.
Based on reporting by Cyber Security News.
