DrayOS Routers Vulnerability Enables Remote Code Execution
ID: 145dcb69-bfa4-58bb-ba9e-ab7e724ea0d7
STIX ID: report--145dcb69-bfa4-58bb-ba9e-ab7e724ea0d7
Feed Name: Cyber Press
Threat Score
Critical unauthenticated remote code execution vulnerability in DrayTek DrayOS WebUI allows specially crafted HTTP(S) requests to cause memory corruption, device crashes, and potentially execute root shell commands on many Vigor router models; vendor firmware updates are available and immediate mitigations include disabling remote WebUI/SSL VPN, enforcing ACLs, using VLAN segmentation or out-of-band management, and applying the listed firmware versions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
