Skip to content
  • Blog Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form

Unauthenticated RCE Flaw Patched in DrayTek Routers

Posted on October 3, 2025October 3, 2025 By CWS

DrayTek on Thursday introduced patches for an unauthenticated distant code execution (RCE) vulnerability affecting DrayOS routers.

Tracked as CVE-2025-10547, the difficulty could be exploited through crafted HTTP or HTTPS requests despatched to a susceptible gadget’s internet consumer interface.

Profitable exploitation of the bug, DrayTek explains in its advisory, might lead to reminiscence corruption and a system crash. In sure circumstances, it might be used to execute arbitrary code remotely, it says.

“Routers are shielded from WAN-based assaults if distant entry to the WebUI and SSL VPN providers is disabled, or if Entry Management Lists (ACLs) are correctly configured,” DrayTek notes.

“Nonetheless, an attacker with entry to the native community might nonetheless exploit the vulnerability through the WebUI. Native entry to the WebUI could be managed on some fashions utilizing LAN facet VLANs and ACLs,” the corporate provides.

The corporate credited ChapsVision safety researcher Pierre-Yves Maes for reporting the vulnerability on July 22.

DrayTek has launched firmware updates that deal with the safety defect in 35 Vigor router fashions, urging customers to replace their gadgets as quickly as potential. Nonetheless, it made no point out of the bug being exploited within the wild.

DrayTek gadgets are broadly utilized by prosumers and SMBs, and are recognized to be widespread targets for hackers. Ransomware teams final yr hit lots of of organizations by exploiting an unknown flaw in DrayTek routers.Commercial. Scroll to proceed studying.

Earlier this yr, widespread Vigor router reboots reported throughout the UK, Australia, and different nations had been blamed on probably malicious TCP connection makes an attempt concentrating on older fashions.

Associated: Organizations Warned of Exploited Meteobridge Vulnerability

Associated: Broadcom Fails to Disclose Zero-Day Exploitation of VMware Vulnerability

Associated: Cisco Patches Zero-Day Flaw Affecting Routers and Switches

Associated: Vulnerabilities Expose Helmholz Industrial Routers to Hacking

Security Week News Tags:DrayTek, Flaw, Patched, RCE, Routers, Unauthenticated

Post navigation

Previous Post: How Passwork 7 Addresses Complexity of Enterprise Security
Next Post: TOTOLINK X6000R Router Vulnerabilities Let Remote Attackers Execute Arbitrary Commands

Related Posts

Amazon Detects 150,000 NPM Packages in Worm-Powered Campaign  Security Week News
FTC Calls on Tech Firms to Resist Foreign Anti-Encryption Demands Security Week News
Russian APT Switches to New Backdoor After Malware Exposed by Researchers Security Week News
Apple Patches 19 WebKit Vulnerabilities  Security Week News
Who’s Really Behind the Mask? Combatting Identity Fraud Security Week News
Legitimate Shellter Pen-Testing Tool Used in Malware Attacks Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Hackers Leveraging WhatsApp That Silently Harvest Logs and Contact Details
  • Elite Cyber Veterans Launch Blast Security with $10M to Turn Cloud Detection into Prevention
  • PoC released for W3 Total Cache Vulnerability that Exposes 1+ Million Websites to RCE Attacks
  • CISA Confirms Exploitation of Recent Oracle Identity Manager Vulnerability
  • 800+ npm Packages and Thousands of GitHub Repos Compromised

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Hackers Leveraging WhatsApp That Silently Harvest Logs and Contact Details
  • Elite Cyber Veterans Launch Blast Security with $10M to Turn Cloud Detection into Prevention
  • PoC released for W3 Total Cache Vulnerability that Exposes 1+ Million Websites to RCE Attacks
  • CISA Confirms Exploitation of Recent Oracle Identity Manager Vulnerability
  • 800+ npm Packages and Thousands of GitHub Repos Compromised

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2025 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark