Security intelligence firm GreyNoise has identified the active exploitation of several DrayTek vulnerabilities, which could be linked to these mysterious reboots that began around March 22, 2025. This incident follows Forescout Technologies’ October 2024 findings that identified 14 previously unknown vulnerabilities in DrayTek routers, including one with the highest possible severity rating of 10. Multiple internet service providers worldwide are reporting widespread disruptions as DrayTek routers enter continuous reboot loops, affecting businesses and consumers alike. ISPs, including Gamma, Zen Internet, ICUK, and Andrews & Arnold in the United Kingdom, confirmed these disruptions, attributing them to attacks targeting unspecified vulnerabilities. Cyber Security News is a Dedicated News Platform For Cyber News, Cyber Attack News, Hacking News & Vulnerability Analysis. CVE-2020-8515: A remote code execution vulnerability affecting multiple DrayTek router models. “The cause has been narrowed down to vulnerable firmware versions on DrayTek routers. Both vulnerabilities have shown active exploitation within the last 24 hours, with 23 and 22 unique attacking IP addresses recorded, respectively. Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. While no activity has been observed in the past 24 hours, 82 unique IP addresses were recorded exploiting this vulnerability in the past 30 days. Security researchers continue to monitor the situation, with GreyNoise tracking exploit attempts in real-time.
This Cyber News was published on cybersecuritynews.com. Publication date: Wed, 26 Mar 2025 11:31:22 +0000