Home > About > Security Advisory >

DrayTek Router Web Management Page Vulnerability

Released Date: 2018-05-18

We have become aware of security reports with DrayTek routers related to the security of web administration when managing DrayTek routers. 

In some circumstances, it may be possible for an attacker to intercept or create an administration session and change settings on your router. The reports appear to show that DNS settings are being altered. Specific improvements have been identified as necessary to combat this and we are in the process of producing and issuing new firmware. You should install that as soon as possible.

Until you have the new firmware installed, you should check your router's DNS settings on your router and correct them if changed (or restore from a config backup). We also recommend only using secured (TLS1.2) connections for web admin (for local and remote admin) and disable remote admin unless needed, or until firmware is updated. The list of updated firmware versions is as follows. We will be uploading the new firmware as soon as possible.

Affected Products and the Fixed Firmware Version

Model Fixed Firmware Version
Vigor2120 3.8.8.2
Vigor2133 3.8.8.2
Vigor2760D 3.8.8.2
Vigor2762 3.8.8.2
Vigor2832 3.8.8.2
Vigor2860 3.8.8
Vigor2862 3.8.8.2
Vigor2862B 3.8.8.2
Vigor2912 3.8.8.2
Vigor2925 3.8.8.2
Vigor2926 3.8.8.2
Vigor2952 3.8.8.2
Vigor3200 3.8.8.2
Vigor3220 3.8.8.2
VigorBX2000 3.8.1.9
Vigor2830nv2 3.8.8.2
Vigor2830 3.8.8.2
Vigor2850 3.8.8.2
Vigor2920 3.8.8.2
Vigor2820 3.7.2
Vigor120_V2 3.7.2
Vigor2110 3.7.2
Vigor2710 3.7.2
Vigor2710e 3.7.2
Vigor2710ne 3.7.2
Contact Technical Support

Should you have any security-related inquiry regarding one of our products, please contact DrayTek Technical Support.