logo

DrayOS Routers Vulnerability Enables Remote Code Execution

ID: 145dcb69-bfa4-58bb-ba9e-ab7e724ea0d7

STIX ID: report--145dcb69-bfa4-58bb-ba9e-ab7e724ea0d7

Feed Name: Cyber Press

Threat Score
75/100

Date Published: 2025-10-03

Date Updated: 2026-04-13

Author: AnuPriya

...
...

Critical unauthenticated remote code execution vulnerability in DrayTek DrayOS WebUI allows specially crafted HTTP(S) requests to cause memory corruption, device crashes, and potentially execute root shell commands on many Vigor router models; vendor firmware updates are available and immediate mitigations include disabling remote WebUI/SSL VPN, enforcing ACLs, using VLAN segmentation or out-of-band management, and applying the listed firmware versions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.