PT-2025-40432 · Draytek · Vigor Routers

Published

2025-10-02

·

Updated

2025-11-11

·

CVE-2025-10547

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions DrayOS routers versions prior to the fixed firmware.
Description A flaw exists in the HTTP CGI request arguments processing component of DrayOS routers, potentially allowing an attacker to execute code remotely (RCE) through memory corruption. This issue stems from an uninitialized variable within the WebUI. Successful exploitation via crafted HTTP or HTTPS requests may lead to memory corruption and system crashes. DrayTek routers are commonly used by small to medium-sized businesses and have been targeted in previous attacks. The vulnerability is exploitable through the WebUI, even with local network access.
Recommendations Update the firmware to the latest version to address the vulnerability.

Fix

Weakness Enumeration

Related Identifiers

BDU:2025-13369
CVE-2025-10547

Affected Products

Vigor Routers