Critical Vulnerability in DrayTek routers

The vulnerability, named (CVE-2022-32548), could expose businesses to possible exploitation by hackers. The vulnerability carries a maximum CVSS v3 severity score of 10.0, categorizing it as critical.

What issues could be caused by this Critical Vulnerability of DrayTek routers?

DrayTek routers with this critical vulnerability could be exploited, potentially leading to these possible threats:

  • Complete device takeover
  • Sensitive information on the router being stolen (e.g. passwords and keys)
  • Stealthy “man-in-the-middle” attacks that can divert information from your router to hackers
  • Access to the internal resources located on the LAN which would normally require a VPN access or to be on the same network
  • Spying on DNS requests and other unencrypted traffic directed to the internet through the router.
  • DDoS attacks – (using the routers as cryptominer bots, for example)

Is my DrayTek router affected?

The vulnerable DrayTek devices and corrective firmware versions are listed below:

Vigor3910 < 4.3.1.1
Vigor1000B < 4.3.1.1
Vigor2962 Series < 4.3.1.1
Vigor2927 Series < 4.4.0
Vigor2927 LTE Series < 4.4.0
Vigor2915 Series < 4.3.3.2
Vigor2952 / 2952P < 3.9.7.2
Vigor3220 Series < 3.9.7.2
Vigor2926 Series < 3.9.8.1
Vigor2926 LTE Series < 3.9.8.1
Vigor2862 Series < 3.9.8.1
Vigor2862 LTE Series < 3.9.8.1
Vigor2620 LTE Series < 3.9.8.1
VigorLTE 200n < 3.9.8.1
Vigor2133 Series < 3.9.6.4
Vigor2762 Series < 3.9.6.4
Vigor167 < 5.1.1
Vigor130 < 3.8.5
VigorNIC 132 < 3.8.5
Vigor165 < 4.2.4
Vigor166 < 4.2.4
Vigor2135 Series < 4.4.2
Vigor2765 Series < 4.4.2
Vigor2766 Series < 4.4.2
Vigor2832 < 3.9.6
Vigor2865 Series < 4.4.0
Vigor2865 LTE Series < 4.4.0
Vigor2866 Series < 4.4.0
Vigor2866 LTE Series < 4.4.0

How to Prevent and Protect your DrayTek router from this Attack?

If you’re using any of the affected Draytek routers that are listed in this article, then we strongly recommend checking the firmware version on your router and if necessary, applying the latest corrective firmware.

What are we doing to help?

We have already been identifying and proactively patching any of our customers who may be using a vulnerable DrayTek device but if you’re concerned that you may be affected and would like support or advice, please don’t hesitate to contact us.