Description
Draytek Vigor Routers firmware versions below 3.9.6/4.2.4, Access Points firmware versions below v1.4.0, Switches firmware versions below 2.6.7, and Myvigor firmware versions below 2.3.2 were discovered to use hardcoded encryption keys which allows attackers to bind any affected device to their own account. Attackers are then able to create WCF and DrayDDNS licenses and synchronize them from the website.
Published: 2023-06-01
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-37930 Draytek Vigor Routers firmware versions below 3.9.6/4.2.4, Access Points firmware versions below v1.4.0, Switches firmware versions below 2.6.7, and Myvigor firmware versions below 2.3.2 were discovered to use hardcoded encryption keys which allows attackers to bind any affected device to their own account. Attackers are then able to create WCF and DrayDDNS licenses and synchronize them from the website.
History

Thu, 09 Jan 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Subscriptions

Draytek Myvigor Vigor1000b Vigor1000b Firmware Vigor130 Vigor130 Firmware Vigor165 Vigor165 Firmware Vigor166 Vigor166 Firmware Vigor167 Vigor167 Firmware Vigor2135ac Vigor2135ac Firmware Vigor2135ax Vigor2135ax Firmware Vigor2135fvac Vigor2135fvac Firmware Vigor2135vac Vigor2135vac Firmware Vigor2620l Vigor2620l Firmware Vigor2620ln Vigor2620ln Firmware Vigor2763ac Vigor2763ac Firmware Vigor2765ac Vigor2765ac Firmware Vigor2765ax Vigor2765ax Firmware Vigor2765vac Vigor2765vac Firmware Vigor2766ac Vigor2766ac Firmware Vigor2766ax Vigor2766ax Firmware Vigor2766vac Vigor2766vac Firmware Vigor2832n Vigor2832n Firmware Vigor2862ac Vigor2862ac Firmware Vigor2862b Vigor2862b Firmware Vigor2862bn Vigor2862bn Firmware Vigor2862l Vigor2862l Firmware Vigor2862lac Vigor2862lac Firmware Vigor2862ln Vigor2862ln Firmware Vigor2862n Vigor2862n Firmware Vigor2862vac Vigor2862vac Firmware Vigor2865ac Vigor2865ac Firmware Vigor2865ax Vigor2865ax Firmware Vigor2865l Vigor2865l Firmware Vigor2865lac Vigor2865lac Firmware Vigor2865vac Vigor2865vac Firmware Vigor2866ac Vigor2866ac Firmware Vigor2866ax Vigor2866ax Firmware Vigor2866l Vigor2866l Firmware Vigor2866lac Vigor2866lac Firmware Vigor2866vac Vigor2866vac Firmware Vigor2915ac Vigor2915ac Firmware Vigor2926 Plus Vigor2926 Plus Firmware Vigor2927ac Vigor2927ac Firmware Vigor2927ax Vigor2927ax Firmware Vigor2927f Vigor2927f Firmware Vigor2927l Vigor2927l Firmware Vigor2927lac Vigor2927lac Firmware Vigor2927vac Vigor2927vac Firmware Vigor2962 Vigor2962 Firmware Vigor3910 Vigor3910 Firmware Vigorap 1000c Vigorap 1000c Firmware Vigorap 1060c Vigorap 1060c Firmware Vigorap 903 Vigorap 903 Firmware Vigorap 906 Vigorap 906 Firmware Vigorap 912c Vigorap 912c Firmware Vigorap 918r Vigorap 918r Firmware Vigorap 960c Vigorap 960c Firmware Vigorlte 200n Vigorlte 200n Firmware Vigorswitch Fx2120 Vigorswitch Fx2120 Firmware Vigorswitch G1080 Vigorswitch G1080 Firmware Vigorswitch G1085 Vigorswitch G1085 Firmware Vigorswitch G1282 Vigorswitch G1282 Firmware Vigorswitch G2100 Vigorswitch G2100 Firmware Vigorswitch G2121 Vigorswitch G2121 Firmware Vigorswitch G2280x Vigorswitch G2280x Firmware Vigorswitch G2540xs Vigorswitch G2540xs Firmware Vigorswitch P1282 Vigorswitch P1282 Firmware Vigorswitch P2100 Vigorswitch P2100 Firmware Vigorswitch P2280x Vigorswitch P2280x Firmware Vigorswitch P2540xs Vigorswitch P2540xs Firmware Vigorswitch Pq2121x Vigorswitch Pq2121x Firmware Vigorswitch Pq2200xb Vigorswitch Pq2200xb Firmware Vigorswitch Q2121x Vigorswitch Q2121x Firmware Vigorswitch Q2200x Vigorswitch Q2200x Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-01-09T17:24:35.184Z

Reserved: 2023-05-22T00:00:00.000Z

Link: CVE-2023-33778

cve-icon Vulnrichment

Updated: 2024-08-02T15:47:06.496Z

cve-icon NVD

Status : Modified

Published: 2023-06-01T04:15:10.313

Modified: 2025-01-09T18:15:26.790

Link: CVE-2023-33778

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses