Draytek Vigor Routers firmware versions below 3.9.6/4.2.4, Access Points firmware versions below v1.4.0, Switches firmware versions below 2.6.7, and Myvigor firmware versions below 2.3.2 were discovered to use hardcoded encryption keys which allows attackers to bind any affected device to their own account. Attackers are then able to create WCF and DrayDDNS licenses and synchronize them from the website.

Project Subscriptions

Vendors Products
Draytek Subscribe
Myvigor Subscribe
Vigor1000b Subscribe
Vigor1000b Firmware Subscribe
Vigor130 Subscribe
Vigor130 Firmware Subscribe
Vigor165 Subscribe
Vigor165 Firmware Subscribe
Vigor166 Subscribe
Vigor166 Firmware Subscribe
Vigor167 Subscribe
Vigor167 Firmware Subscribe
Vigor2135ac Subscribe
Vigor2135ac Firmware Subscribe
Vigor2135ax Subscribe
Vigor2135ax Firmware Subscribe
Vigor2135fvac Subscribe
Vigor2135fvac Firmware Subscribe
Vigor2135vac Subscribe
Vigor2135vac Firmware Subscribe
Vigor2620l Subscribe
Vigor2620l Firmware Subscribe
Vigor2620ln Subscribe
Vigor2620ln Firmware Subscribe
Vigor2763ac Subscribe
Vigor2763ac Firmware Subscribe
Vigor2765ac Subscribe
Vigor2765ac Firmware Subscribe
Vigor2765ax Subscribe
Vigor2765ax Firmware Subscribe
Vigor2765vac Subscribe
Vigor2765vac Firmware Subscribe
Vigor2766ac Subscribe
Vigor2766ac Firmware Subscribe
Vigor2766ax Subscribe
Vigor2766ax Firmware Subscribe
Vigor2766vac Subscribe
Vigor2766vac Firmware Subscribe
Vigor2832n Subscribe
Vigor2832n Firmware Subscribe
Vigor2862ac Subscribe
Vigor2862ac Firmware Subscribe
Vigor2862b Subscribe
Vigor2862b Firmware Subscribe
Vigor2862bn Subscribe
Vigor2862bn Firmware Subscribe
Vigor2862l Subscribe
Vigor2862l Firmware Subscribe
Vigor2862lac Subscribe
Vigor2862lac Firmware Subscribe
Vigor2862ln Subscribe
Vigor2862ln Firmware Subscribe
Vigor2862n Subscribe
Vigor2862n Firmware Subscribe
Vigor2862vac Subscribe
Vigor2862vac Firmware Subscribe
Vigor2865ac Subscribe
Vigor2865ac Firmware Subscribe
Vigor2865ax Subscribe
Vigor2865ax Firmware Subscribe
Vigor2865l Subscribe
Vigor2865l Firmware Subscribe
Vigor2865lac Subscribe
Vigor2865lac Firmware Subscribe
Vigor2865vac Subscribe
Vigor2865vac Firmware Subscribe
Vigor2866ac Subscribe
Vigor2866ac Firmware Subscribe
Vigor2866ax Subscribe
Vigor2866ax Firmware Subscribe
Vigor2866l Subscribe
Vigor2866l Firmware Subscribe
Vigor2866lac Subscribe
Vigor2866lac Firmware Subscribe
Vigor2866vac Subscribe
Vigor2866vac Firmware Subscribe
Vigor2915ac Subscribe
Vigor2915ac Firmware Subscribe
Vigor2926 Plus Subscribe
Vigor2926 Plus Firmware Subscribe
Vigor2927ac Subscribe
Vigor2927ac Firmware Subscribe
Vigor2927ax Subscribe
Vigor2927ax Firmware Subscribe
Vigor2927f Subscribe
Vigor2927f Firmware Subscribe
Vigor2927l Subscribe
Vigor2927l Firmware Subscribe
Vigor2927lac Subscribe
Vigor2927lac Firmware Subscribe
Vigor2927vac Subscribe
Vigor2927vac Firmware Subscribe
Vigor2962 Subscribe
Vigor2962 Firmware Subscribe
Vigor3910 Subscribe
Vigor3910 Firmware Subscribe
Vigorap 1000c Subscribe
Vigorap 1000c Firmware Subscribe
Vigorap 1060c Subscribe
Vigorap 1060c Firmware Subscribe
Vigorap 903 Subscribe
Vigorap 903 Firmware Subscribe
Vigorap 906 Subscribe
Vigorap 906 Firmware Subscribe
Vigorap 912c Subscribe
Vigorap 912c Firmware Subscribe
Vigorap 918r Subscribe
Vigorap 918r Firmware Subscribe
Vigorap 960c Subscribe
Vigorap 960c Firmware Subscribe
Vigorlte 200n Subscribe
Vigorlte 200n Firmware Subscribe
Vigorswitch Fx2120 Subscribe
Vigorswitch Fx2120 Firmware Subscribe
Vigorswitch G1080 Subscribe
Vigorswitch G1080 Firmware Subscribe
Vigorswitch G1085 Subscribe
Vigorswitch G1085 Firmware Subscribe
Vigorswitch G1282 Subscribe
Vigorswitch G1282 Firmware Subscribe
Vigorswitch G2100 Subscribe
Vigorswitch G2100 Firmware Subscribe
Vigorswitch G2121 Subscribe
Vigorswitch G2121 Firmware Subscribe
Vigorswitch G2280x Subscribe
Vigorswitch G2280x Firmware Subscribe
Vigorswitch G2540xs Subscribe
Vigorswitch G2540xs Firmware Subscribe
Vigorswitch P1282 Subscribe
Vigorswitch P1282 Firmware Subscribe
Vigorswitch P2100 Subscribe
Vigorswitch P2100 Firmware Subscribe
Vigorswitch P2280x Subscribe
Vigorswitch P2280x Firmware Subscribe
Vigorswitch P2540xs Subscribe
Vigorswitch P2540xs Firmware Subscribe
Vigorswitch Pq2121x Subscribe
Vigorswitch Pq2121x Firmware Subscribe
Vigorswitch Pq2200xb Subscribe
Vigorswitch Pq2200xb Firmware Subscribe
Vigorswitch Q2121x Subscribe
Vigorswitch Q2121x Firmware Subscribe
Vigorswitch Q2200x Subscribe
Vigorswitch Q2200x Firmware Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2023-37930 Draytek Vigor Routers firmware versions below 3.9.6/4.2.4, Access Points firmware versions below v1.4.0, Switches firmware versions below 2.6.7, and Myvigor firmware versions below 2.3.2 were discovered to use hardcoded encryption keys which allows attackers to bind any affected device to their own account. Attackers are then able to create WCF and DrayDDNS licenses and synchronize them from the website.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 09 Jan 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-01-09T17:24:35.184Z

Reserved: 2023-05-22T00:00:00

Link: CVE-2023-33778

cve-icon Vulnrichment

Updated: 2024-08-02T15:47:06.496Z

cve-icon NVD

Status : Modified

Published: 2023-06-01T04:15:10.313

Modified: 2025-01-09T18:15:26.790

Link: CVE-2023-33778

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses