Critical RCE vulnerability affects 29 DrayTek router models
Researchers from security firm Trellix have discovered an unauthenticated remote code execution (RCE) vulnerability affecting 29 models of DrayTek routers.
Notably, the affected products are all from the enterprise Virgo line.
This vulnerability is tracked under the code CVE-2022-32548 and is scored 10, the maximum score on the CVSSv3 threat scale. For that reason, CVE-2022-32548 is considered extremely dangerous and requires immediate remedial and mitigation measures.
To exploit CVE-2022-32548, hackers do not need login information or any interaction of the victim. The default configuration of the device allows the attack to be carried out through the internet and LAN.
Hackers successfully exploiting the CVE-2022-32548 vulnerability can perform the following actions:
- Full control of the device.
- Set up the foundation for man-in-the-middle attacks.
- Change DNS settings.
- Use routers as bots for DDoS attacks or cryptocurrency mining.
Widespread influence
DrayTek Vigor devices became very popular during the pandemic due to the wave of working from home. They are reasonably priced products for VPN access to SME networks.
A quick Shodan search results in over 700,000 DrayTek Virgo devices connected to the internet. Most of these devices are located in the UK, Vietnam, the Netherlands and Australia.
Trellix decided to evaluate the security of one of DrayTek's top router models. The results show that the web management interface has a buffer overflow on the login page.
Using a specially generated pair of credentials as a base64 encoded string in the login fields, a hacker could enable the vulnerability and take control of the device's operating system.
Researchers found at least 200,000 of the routers discovered on Shodan expose a vulnerable service on the internet and thus can be easily exploited without user interaction or any other any other special prerequisites.
Of the remaining 500,000, many are exploitable with one-click attacks but only through LAN so the attack surface is smaller.
The list of affected devices includes:
- Vigor3910
- Vigor1000B
- Vigor2962 Series
- Vigor2927 Series
- Vigor2927 LTE Series
- Vigor2915 Series
- Vigor2952 / 2952P
- Vigor3220 Series
- Vigor2926 Series
- Vigor2926 LTE Series
- Vigor2862 Series
- Vigor2862 LTE Series
- Vigor2620 LTE Series
- VigorLTE 200n
- Vigor2133 Series
- Vigor2762 Series
- Vigor167
- Vigor130
- VigorNIC 132
- Vigor165
- Vigor166
- Vigor2135 Series
- Vigor2765 Series
- Vigor2766 Series
- Vigor2832
- Vigor2865 Series
- Vigor2865 LTE Series
- Vigor2866 Series
- Vigor2866 LTE Series
DrayTek quickly released security updates for the above devices. If you are using the devices listed above, find and download the latest firmware then install to patch the vulnerability.
- How to change Modem login password and Vigor Draytek Router
- GitLab patches critical vulnerability that allows hackers to take control of accounts
- How to set up and configure DDNS on Draytek router
- New privilege escalation vulnerability called 'Dirty Pipe' is threatening all Linux distros
- Zalo PC has a serious RCE error, you should be careful when receiving attachments
- Critical Vulnerability Discovered in 3 WordPress Plugins, Affects 84,000 Websites
- 'Printer Catastrophe' Vulnerability Threatens All Versions of Windows
- Log4Shell zero-day vulnerability discovered, the new nightmare of enterprises