We have become aware of security reports with DrayTek routers related to the security of web administration when managing DrayTek routers.
In some circumstances, it may be possible for an attacker to intercept or create an administration session and change settings on your router. The reports appear to show that DNS settings are being altered. Specific improvements have been identified as necessary to combat this and we are in the process of producing and issuing new firmware. You should install that as soon as possible.
Until you have the new firmware installed, you should check your router's DNS settings on your router and correct them if changed (or restore from a config backup). We also recommend only using secured (TLS1.2) connections for web admin (for local and remote admin) and disable remote admin unless needed, or until firmware is updated. The list of updated firmware versions is as follows. We will be uploading the new firmware as soon as possible.
Press Contacts: firstname.lastname@example.org
DrayTek is a manufacturer of broadband CPE (Customer Premises Equipment), including firewalls, VPN devices, load-balancing routers, wireless access points, and switches. Our goal is to provide reliable and high-integrated networking solutions at an affordable price, become the reliable networking partner of small and medium-sized businesses.