CVE-2023-33778
01.06.2023, 04:15
Draytek Vigor Routers firmware versions below 3.9.6/4.2.4, Access Points firmware versions below v1.4.0, Switches firmware versions below 2.6.7, and Myvigor firmware versions below 2.3.2 were discovered to use hardcoded encryption keys which allows attackers to bind any affected device to their own account. Attackers are then able to create WCF and DrayDDNS licenses and synchronize them from the website.Enginsight
Vendor | Product | Version |
---|---|---|
draytek | myvigor | 𝑥 < 2.3.2 |
draytek | vigorswitch_pq2200xb_firmware | 𝑥 < 2.6.7 |
draytek | vigorswitch_pq2121x_firmware | 𝑥 < 2.6.7 |
draytek | vigorswitch_p2540xs_firmware | 𝑥 < 2.6.7 |
draytek | vigorswitch_p2280x_firmware | 𝑥 < 2.6.7 |
draytek | vigorswitch_p2100_firmware | 𝑥 < 2.6.7 |
draytek | vigorswitch_q2200x_firmware | 𝑥 < 2.6.7 |
draytek | vigorswitch_q2121x_firmware | 𝑥 < 2.6.7 |
draytek | vigorswitch_g2540xs_firmware | 𝑥 < 2.6.7 |
draytek | vigorswitch_g2280x_firmware | 𝑥 < 2.6.7 |
draytek | vigorswitch_g2121_firmware | 𝑥 < 2.6.7 |
draytek | vigorswitch_g2100_firmware | 𝑥 < 2.6.7 |
draytek | vigorswitch_fx2120_firmware | 𝑥 < 2.6.7 |
draytek | vigorswitch_p1282_firmware | 𝑥 < 2.6.7 |
draytek | vigorswitch_g1282_firmware | 𝑥 < 2.6.7 |
draytek | vigorswitch_g1085_firmware | 𝑥 < 2.6.7 |
draytek | vigorswitch_g1080_firmware | 𝑥 < 2.6.7 |
draytek | vigorap_903_firmware | 𝑥 < 1.4.0 |
draytek | vigorap_912c_firmware | 𝑥 < 1.4.0 |
draytek | vigorap_918r_firmware | 𝑥 < 1.4.0 |
draytek | vigorap_1060c_firmware | 𝑥 < 1.4.0 |
draytek | vigorap_906_firmware | 𝑥 < 1.4.0 |
draytek | vigorap_960c_firmware | 𝑥 < 1.4.0 |
draytek | vigorap_1000c_firmware | 𝑥 < 1.4.0 |
draytek | vigor2766ac_firmware | 𝑥 < 3.9.6 |
draytek | vigor2766ac_firmware | 4.0.0 ≤ 𝑥 < 4.2.4 |
draytek | vigor2766ax_firmware | 𝑥 < 3.9.6 |
draytek | vigor2766ax_firmware | 4.0.0 ≤ 𝑥 < 4.2.4 |
draytek | vigor2766vac_firmware | 𝑥 < 3.9.6 |
draytek | vigor2766vac_firmware | 4.0.0 ≤ 𝑥 < 4.2.4 |
draytek | vigor2765ax_firmware | 𝑥 < 3.9.6 |
draytek | vigor2765ax_firmware | 4.0.0 ≤ 𝑥 < 4.2.4 |
draytek | vigor2765vac_firmware | 𝑥 < 3.9.6 |
draytek | vigor2765vac_firmware | 4.0.0 ≤ 𝑥 < 4.2.4 |
draytek | vigor2765ac_firmware | 𝑥 < 3.9.6 |
draytek | vigor2765ac_firmware | 4.0.0 ≤ 𝑥 < 4.2.4 |
draytek | vigor2763ac_firmware | 𝑥 < 3.9.6 |
draytek | vigor2763ac_firmware | 4.0.0 ≤ 𝑥 < 4.2.4 |
draytek | vigor2620l_firmware | 𝑥 < 3.9.6 |
draytek | vigor2620l_firmware | 4.0.0 ≤ 𝑥 < 4.2.4 |
draytek | vigor2620ln_firmware | 𝑥 < 3.9.6 |
draytek | vigor2620ln_firmware | 4.0.0 ≤ 𝑥 < 4.2.4 |
draytek | vigorlte_200n_firmware | 𝑥 < 3.9.6 |
draytek | vigorlte_200n_firmware | 4.0.0 ≤ 𝑥 < 4.2.4 |
draytek | vigor2915ac_firmware | 𝑥 < 3.9.6 |
draytek | vigor2915ac_firmware | 4.0.0 ≤ 𝑥 < 4.2.4 |
draytek | vigor2135ac_firmware | 𝑥 < 3.9.6 |
draytek | vigor2135ac_firmware | 4.0.0 ≤ 𝑥 < 4.2.4 |
draytek | vigor2135ax_firmware | 𝑥 < 3.9.6 |
draytek | vigor2135ax_firmware | 4.0.0 ≤ 𝑥 < 4.2.4 |
draytek | vigor2135fvac_firmware | 𝑥 < 3.9.6 |
draytek | vigor2135fvac_firmware | 4.0.0 ≤ 𝑥 < 4.2.4 |
draytek | vigor2135vac_firmware | 𝑥 < 3.9.6 |
draytek | vigor2135vac_firmware | 4.0.0 ≤ 𝑥 < 4.2.4 |
draytek | vigor2866ax_firmware | 𝑥 < 3.9.6 |
draytek | vigor2866ax_firmware | 4.0.0 ≤ 𝑥 < 4.2.4 |
draytek | vigor2866ac_firmware | 𝑥 < 3.9.6 |
draytek | vigor2866ac_firmware | 4.0.0 ≤ 𝑥 < 4.2.4 |
draytek | vigor2866vac_firmware | 𝑥 < 3.9.6 |
draytek | vigor2866vac_firmware | 4.0.0 ≤ 𝑥 < 4.2.4 |
draytek | vigor2866l_firmware | 𝑥 < 3.9.6 |
draytek | vigor2866l_firmware | 4.0.0 ≤ 𝑥 < 4.2.4 |
draytek | vigor2866lac_firmware | 𝑥 < 3.9.6 |
draytek | vigor2866lac_firmware | 4.0.0 ≤ 𝑥 < 4.2.4 |
draytek | vigor2865ac_firmware | 𝑥 < 3.9.6 |
draytek | vigor2865ac_firmware | 4.0.0 ≤ 𝑥 < 4.2.4 |
draytek | vigor2865ax_firmware | 𝑥 < 3.9.6 |
draytek | vigor2865ax_firmware | 4.0.0 ≤ 𝑥 < 4.2.4 |
draytek | vigor2865vac_firmware | 𝑥 < 3.9.6 |
draytek | vigor2865vac_firmware | 4.0.0 ≤ 𝑥 < 4.2.4 |
draytek | vigor2865l_firmware | 𝑥 < 3.9.6 |
draytek | vigor2865l_firmware | 4.0.0 ≤ 𝑥 < 4.2.4 |
draytek | vigor2865lac_firmware | 𝑥 < 3.9.6 |
draytek | vigor2865lac_firmware | 4.0.0 ≤ 𝑥 < 4.2.4 |
draytek | vigor2862n_firmware | 𝑥 < 3.9.6 |
draytek | vigor2862n_firmware | 4.0.0 ≤ 𝑥 < 4.2.4 |
draytek | vigor2862ac_firmware | 𝑥 < 3.9.6 |
draytek | vigor2862ac_firmware | 4.0.0 ≤ 𝑥 < 4.2.4 |
draytek | vigor2862vac_firmware | 𝑥 < 3.9.6 |
draytek | vigor2862vac_firmware | 4.0.0 ≤ 𝑥 < 4.2.4 |
draytek | vigor2862b_firmware | 𝑥 < 3.9.6 |
draytek | vigor2862b_firmware | 4.0.0 ≤ 𝑥 < 4.2.4 |
draytek | vigor2862bn_firmware | 𝑥 < 3.9.6 |
draytek | vigor2862bn_firmware | 4.0.0 ≤ 𝑥 < 4.2.4 |
draytek | vigor2862l_firmware | 𝑥 < 3.9.6 |
draytek | vigor2862l_firmware | 4.0.0 ≤ 𝑥 < 4.2.4 |
draytek | vigor2862lac_firmware | 𝑥 < 3.9.6 |
draytek | vigor2862lac_firmware | 4.0.0 ≤ 𝑥 < 4.2.4 |
draytek | vigor2862ln_firmware | 𝑥 < 3.9.6 |
draytek | vigor2862ln_firmware | 4.0.0 ≤ 𝑥 < 4.2.4 |
draytek | vigor2832n_firmware | 𝑥 < 3.9.6 |
draytek | vigor2832n_firmware | 4.0.0 ≤ 𝑥 < 4.2.4 |
draytek | vigor2927ax_firmware | 𝑥 < 3.9.6 |
draytek | vigor2927ax_firmware | 4.0.0 ≤ 𝑥 < 4.2.4 |
draytek | vigor2927ac_firmware | 𝑥 < 3.9.6 |
draytek | vigor2927ac_firmware | 4.0.0 ≤ 𝑥 < 4.2.4 |
draytek | vigor2927vac_firmware | 𝑥 < 3.9.6 |
draytek | vigor2927vac_firmware | 4.0.0 ≤ 𝑥 < 4.2.4 |
draytek | vigor2927f_firmware | 𝑥 < 3.9.6 |
draytek | vigor2927f_firmware | 4.0.0 ≤ 𝑥 < 4.2.4 |
draytek | vigor2927l_firmware | 𝑥 < 3.9.6 |
draytek | vigor2927l_firmware | 4.0.0 ≤ 𝑥 < 4.2.4 |
draytek | vigor2927lac_firmware | 𝑥 < 3.9.6 |
draytek | vigor2927lac_firmware | 4.0.0 ≤ 𝑥 < 4.2.4 |
draytek | vigor2926_plus_firmware | 𝑥 < 3.9.6 |
draytek | vigor2926_plus_firmware | 4.0.0 ≤ 𝑥 < 4.2.4 |
draytek | vigor2962_firmware | 𝑥 < 3.9.6 |
draytek | vigor2962_firmware | 4.0.0 ≤ 𝑥 < 4.2.4 |
draytek | vigor1000b_firmware | 𝑥 < 3.9.6 |
draytek | vigor1000b_firmware | 4.0.0 ≤ 𝑥 < 4.2.4 |
draytek | vigor3910_firmware | 𝑥 < 3.9.6 |
draytek | vigor3910_firmware | 4.0.0 ≤ 𝑥 < 4.2.4 |
draytek | vigor165_firmware | 𝑥 < 3.9.6 |
draytek | vigor165_firmware | 4.0.0 ≤ 𝑥 < 4.2.4 |
draytek | vigor166_firmware | 𝑥 < 3.9.6 |
draytek | vigor166_firmware | 4.0.0 ≤ 𝑥 < 4.2.4 |
draytek | vigor130_firmware | 𝑥 < 3.9.6 |
draytek | vigor130_firmware | 4.0.0 ≤ 𝑥 < 4.2.4 |
draytek | vigor167_firmware | 𝑥 < 3.9.6 |
draytek | vigor167_firmware | 4.0.0 ≤ 𝑥 < 4.2.4 |
𝑥
= Vulnerable software versions