Draytek warns vigor routers can have serious security defects: this is what we know




  • Draytek Patches CVE-2025-10547, a firmware failure that enables blockages or the execution of the remote code
  • Vulnerability affects the routers with exposed webui or poorly configured acl; Local access also exploitable
  • Vigor routers are common in SMEs, which makes them attractive objectives for persistent cyber attacks

The Red Draytek equipment manufacturer has paved a dangerous vulnerability found in dozens of models of commercial vigor routors, and is urging users to apply the solution as soon as possible.

In a security notice, Draytek said he discovered a vulnerability of “uninitiated variables in the firmware” in Droyos (the vigor routers of the operating system) that, if exploited, could cause memory corruption or system blockages. There is also a “potential in certain circumstances” to use the error for the execution of the remote code.



Leave a Comment

Your email address will not be published. Required fields are marked *