logo

DrayTek warns of remote code execution bug in Vigor routers

ID: 532cc1bf-a3cd-56db-b5bb-1cf4d3887da1

STIX ID: report--532cc1bf-a3cd-56db-b5bb-1cf4d3887da1

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2025-10-02

Date Updated: 2026-07-18

Author: Bill Toulas

...
...

DrayTek disclosed CVE-2025-10547, an unauthenticated remote code execution flaw in numerous Vigor router models exploitable via crafted HTTP/HTTPS requests to the WebUI; a researcher developed and tested an exploit and DrayTek published firmware updates and mitigation guidance for affected models, urging administrators to apply patches or restrict WebUI access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.