Researchers have identified fourteen new vulnerabilities in DrayTek Vigor routers, including a critical remote code execution flaw rated 10 out of 10 on the CVSS severity scale. Recent reports from the FBI indicate that Chinese government spies exploited three vulnerabilities in DrayTek routers to create a botnet comprising 260,000 devices. These vulnerabilities pose a substantial threat, potentially allowing cybercriminals to seize control of affected devices to steal sensitive data, deploy ransomware, and launch denial-of-service attacks. These vulnerabilities can be exploited together to gain remote root access to the host operating system of affected devices. DrayTek, a Taiwanese networking equipment maker, offers advanced routers with VPN, firewalls, and bandwidth management for residential and business use. DrayTek routers have been consistently targeted by threat groups, especially Chinese advanced persistent threats (APTs). The discovery of these vulnerabilities underscores the critical need for businesses to secure their network infrastructure against increasingly sophisticated cyber threats. Alarmingly, research from Forescout’s Vedere Labs has revealed that over 704,000 of these devices have their web interfaces exposed to the public internet, making them particularly vulnerable to exploitation.
This Cyber News was published on cybersecuritynews.com. Publication date: Thu, 03 Oct 2024 07:10:35 +0000