Draytek Vigor Routers firmware versions below 3.9.6/4.2.4, Access Points firmware versions below v1.4.0, Switches firmware versions below 2.6.7, and Myvigor firmware versions below 2.3.2 were discovered to use hardcoded encryption keys which allows attackers to bind any affected device to their own account. Attackers are then able to create WCF and DrayDDNS licenses and synchronize them from the website.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Draytek
Subscribe
|
Myvigor
Subscribe
Vigor1000b
Subscribe
Vigor1000b Firmware
Subscribe
Vigor130
Subscribe
Vigor130 Firmware
Subscribe
Vigor165
Subscribe
Vigor165 Firmware
Subscribe
Vigor166
Subscribe
Vigor166 Firmware
Subscribe
Vigor167
Subscribe
Vigor167 Firmware
Subscribe
Vigor2135ac
Subscribe
Vigor2135ac Firmware
Subscribe
Vigor2135ax
Subscribe
Vigor2135ax Firmware
Subscribe
Vigor2135fvac
Subscribe
Vigor2135fvac Firmware
Subscribe
Vigor2135vac
Subscribe
Vigor2135vac Firmware
Subscribe
Vigor2620l
Subscribe
Vigor2620l Firmware
Subscribe
Vigor2620ln
Subscribe
Vigor2620ln Firmware
Subscribe
Vigor2763ac
Subscribe
Vigor2763ac Firmware
Subscribe
Vigor2765ac
Subscribe
Vigor2765ac Firmware
Subscribe
Vigor2765ax
Subscribe
Vigor2765ax Firmware
Subscribe
Vigor2765vac
Subscribe
Vigor2765vac Firmware
Subscribe
Vigor2766ac
Subscribe
Vigor2766ac Firmware
Subscribe
Vigor2766ax
Subscribe
Vigor2766ax Firmware
Subscribe
Vigor2766vac
Subscribe
Vigor2766vac Firmware
Subscribe
Vigor2832n
Subscribe
Vigor2832n Firmware
Subscribe
Vigor2862ac
Subscribe
Vigor2862ac Firmware
Subscribe
Vigor2862b
Subscribe
Vigor2862b Firmware
Subscribe
Vigor2862bn
Subscribe
Vigor2862bn Firmware
Subscribe
Vigor2862l
Subscribe
Vigor2862l Firmware
Subscribe
Vigor2862lac
Subscribe
Vigor2862lac Firmware
Subscribe
Vigor2862ln
Subscribe
Vigor2862ln Firmware
Subscribe
Vigor2862n
Subscribe
Vigor2862n Firmware
Subscribe
Vigor2862vac
Subscribe
Vigor2862vac Firmware
Subscribe
Vigor2865ac
Subscribe
Vigor2865ac Firmware
Subscribe
Vigor2865ax
Subscribe
Vigor2865ax Firmware
Subscribe
Vigor2865l
Subscribe
Vigor2865l Firmware
Subscribe
Vigor2865lac
Subscribe
Vigor2865lac Firmware
Subscribe
Vigor2865vac
Subscribe
Vigor2865vac Firmware
Subscribe
Vigor2866ac
Subscribe
Vigor2866ac Firmware
Subscribe
Vigor2866ax
Subscribe
Vigor2866ax Firmware
Subscribe
Vigor2866l
Subscribe
Vigor2866l Firmware
Subscribe
Vigor2866lac
Subscribe
Vigor2866lac Firmware
Subscribe
Vigor2866vac
Subscribe
Vigor2866vac Firmware
Subscribe
Vigor2915ac
Subscribe
Vigor2915ac Firmware
Subscribe
Vigor2926 Plus
Subscribe
Vigor2926 Plus Firmware
Subscribe
Vigor2927ac
Subscribe
Vigor2927ac Firmware
Subscribe
Vigor2927ax
Subscribe
Vigor2927ax Firmware
Subscribe
Vigor2927f
Subscribe
Vigor2927f Firmware
Subscribe
Vigor2927l
Subscribe
Vigor2927l Firmware
Subscribe
Vigor2927lac
Subscribe
Vigor2927lac Firmware
Subscribe
Vigor2927vac
Subscribe
Vigor2927vac Firmware
Subscribe
Vigor2962
Subscribe
Vigor2962 Firmware
Subscribe
Vigor3910
Subscribe
Vigor3910 Firmware
Subscribe
Vigorap 1000c
Subscribe
Vigorap 1000c Firmware
Subscribe
Vigorap 1060c
Subscribe
Vigorap 1060c Firmware
Subscribe
Vigorap 903
Subscribe
Vigorap 903 Firmware
Subscribe
Vigorap 906
Subscribe
Vigorap 906 Firmware
Subscribe
Vigorap 912c
Subscribe
Vigorap 912c Firmware
Subscribe
Vigorap 918r
Subscribe
Vigorap 918r Firmware
Subscribe
Vigorap 960c
Subscribe
Vigorap 960c Firmware
Subscribe
Vigorlte 200n
Subscribe
Vigorlte 200n Firmware
Subscribe
Vigorswitch Fx2120
Subscribe
Vigorswitch Fx2120 Firmware
Subscribe
Vigorswitch G1080
Subscribe
Vigorswitch G1080 Firmware
Subscribe
Vigorswitch G1085
Subscribe
Vigorswitch G1085 Firmware
Subscribe
Vigorswitch G1282
Subscribe
Vigorswitch G1282 Firmware
Subscribe
Vigorswitch G2100
Subscribe
Vigorswitch G2100 Firmware
Subscribe
Vigorswitch G2121
Subscribe
Vigorswitch G2121 Firmware
Subscribe
Vigorswitch G2280x
Subscribe
Vigorswitch G2280x Firmware
Subscribe
Vigorswitch G2540xs
Subscribe
Vigorswitch G2540xs Firmware
Subscribe
Vigorswitch P1282
Subscribe
Vigorswitch P1282 Firmware
Subscribe
Vigorswitch P2100
Subscribe
Vigorswitch P2100 Firmware
Subscribe
Vigorswitch P2280x
Subscribe
Vigorswitch P2280x Firmware
Subscribe
Vigorswitch P2540xs
Subscribe
Vigorswitch P2540xs Firmware
Subscribe
Vigorswitch Pq2121x
Subscribe
Vigorswitch Pq2121x Firmware
Subscribe
Vigorswitch Pq2200xb
Subscribe
Vigorswitch Pq2200xb Firmware
Subscribe
Vigorswitch Q2121x
Subscribe
Vigorswitch Q2121x Firmware
Subscribe
Vigorswitch Q2200x
Subscribe
Vigorswitch Q2200x Firmware
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-37930 | Draytek Vigor Routers firmware versions below 3.9.6/4.2.4, Access Points firmware versions below v1.4.0, Switches firmware versions below 2.6.7, and Myvigor firmware versions below 2.3.2 were discovered to use hardcoded encryption keys which allows attackers to bind any affected device to their own account. Attackers are then able to create WCF and DrayDDNS licenses and synchronize them from the website. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 09 Jan 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-01-09T17:24:35.184Z
Reserved: 2023-05-22T00:00:00
Link: CVE-2023-33778
Updated: 2024-08-02T15:47:06.496Z
Status : Modified
Published: 2023-06-01T04:15:10.313
Modified: 2025-01-09T18:15:26.790
Link: CVE-2023-33778
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD