Researchers identified eight CVEs, including weaknesses in authentication mechanisms, kernel module updates, and protocol implementations, which could allow attackers to bypass security controls, execute arbitrary code, or crash devices. A series of critical vulnerabilities in DrayTek Vigor routers widely deployed in small office/home office (SOHO) environments have been uncovered, exposing devices to remote code execution (RCE), denial-of-service (DoS) attacks, and credential theft. As attackers increasingly target edge devices, vendors must prioritize transparent security practices, and users must demand them. The flaws discovered during firmware reverse-engineering efforts highlight systemic security weaknesses in routers that act as gateways between local networks and the internet. These flaws collectively enable unauthenticated attackers to hijack firmware update mechanisms and deploy persistent payloads. Cyber Security News is a Dedicated News Platform For Cyber News, Cyber Attack News, Hacking News & Vulnerability Analysis.
This Cyber News was published on cybersecuritynews.com. Publication date: Fri, 07 Mar 2025 12:30:10 +0000