CWE
798
Advisory Published
Updated

CVE-2023-33778

First published: Thu Jun 01 2023(Updated: )

Draytek Vigor Routers firmware versions below 3.9.6/4.2.4, Access Points firmware versions below v1.4.0, Switches firmware versions below 2.6.7, and Myvigor firmware versions below 2.3.2 were discovered to use hardcoded encryption keys which allows attackers to bind any affected device to their own account. Attackers are then able to create WCF and DrayDDNS licenses and synchronize them from the website.

Credit: cve@mitre.org

Affected SoftwareAffected VersionHow to fix
Draytek Myvigor<2.3.2
Draytek Vigorswitch Pq2200xb Firmware<2.6.7
Draytek Vigorswitch Pq2200xb
Draytek Vigorswitch Pq2121x Firmware<2.6.7
Draytek Vigorswitch Pq2121x
Draytek Vigorswitch P2540xs Firmware<2.6.7
Draytek Vigorswitch P2540xs
Draytek Vigorswitch P2280x Firmware<2.6.7
Draytek Vigorswitch P2280x
Draytek Vigorswitch P2100 Firmware<2.6.7
Draytek Vigorswitch P2100
Draytek Vigorswitch Q2200x Firmware<2.6.7
Draytek Vigorswitch Q2200x
Draytek Vigorswitch Q2121x Firmware<2.6.7
Draytek Vigorswitch Q2121x
Draytek Vigorswitch G2540xs Firmware<2.6.7
Draytek Vigorswitch G2540xs
Draytek Vigorswitch G2280x Firmware<2.6.7
Draytek Vigorswitch G2280x
Draytek Vigorswitch G2121 Firmware<2.6.7
Draytek Vigorswitch G2121
Draytek Vigorswitch G2100 Firmware<2.6.7
Draytek Vigorswitch G2100
Draytek Vigorswitch Fx2120 Firmware<2.6.7
Draytek Vigorswitch Fx2120
Draytek Vigorswitch P1282 Firmware<2.6.7
Draytek Vigorswitch P1282
Draytek Vigorswitch G1282 Firmware<2.6.7
Draytek Vigorswitch G1282
Draytek Vigorswitch G1085 Firmware<2.6.7
Draytek Vigorswitch G1085
Draytek Vigorswitch G1080 Firmware<2.6.7
Draytek Vigorswitch G1080
Draytek Vigorap 903 Firmware<1.4.0
Draytek Vigorap 903
Draytek Vigorap 912c Firmware<1.4.0
Draytek Vigorap 912c
Draytek Vigorap 918r Firmware<1.4.0
Draytek Vigorap 918r
Draytek Vigorap 1060c Firmware<1.4.0
Draytek Vigorap 1060c
Draytek Vigorap 906 Firmware<1.4.0
Draytek Vigorap 906
Draytek Vigorap 960c Firmware<1.4.0
Draytek Vigorap 960c
Draytek Vigorap 1000c Firmware<1.4.0
Draytek VigorAP 1000C
Draytek Vigor2766ac Firmware<3.9.6
Draytek Vigor2766ac Firmware>=4.0.0<4.2.4
Draytek Vigor2766ac
Draytek Vigor2766ax Firmware<3.9.6
Draytek Vigor2766ax Firmware>=4.0.0<4.2.4
Draytek Vigor2766ax
Draytek Vigor2766vac Firmware<3.9.6
Draytek Vigor2766vac Firmware>=4.0.0<4.2.4
Draytek Vigor2766vac
Draytek Vigor2765ax Firmware<3.9.6
Draytek Vigor2765ax Firmware>=4.0.0<4.2.4
Draytek Vigor2765ax
Draytek Vigor2765vac Firmware<3.9.6
Draytek Vigor2765vac Firmware>=4.0.0<4.2.4
Draytek Vigor2765vac
Draytek Vigor2765ac Firmware<3.9.6
Draytek Vigor2765ac Firmware>=4.0.0<4.2.4
Draytek Vigor2765ac
Draytek Vigor2763ac Firmware<3.9.6
Draytek Vigor2763ac Firmware>=4.0.0<4.2.4
Draytek Vigor2763ac
Draytek Vigor2620l Firmware<3.9.6
Draytek Vigor2620l Firmware>=4.0.0<4.2.4
Draytek Vigor2620l
Draytek Vigor2620ln Firmware<3.9.6
Draytek Vigor2620ln Firmware>=4.0.0<4.2.4
Draytek Vigor2620ln
Draytek Vigorlte 200n Firmware<3.9.6
Draytek Vigorlte 200n Firmware>=4.0.0<4.2.4
Draytek Vigorlte 200n
Draytek Vigor2915ac Firmware<3.9.6
Draytek Vigor2915ac Firmware>=4.0.0<4.2.4
Draytek Vigor2915ac
Draytek Vigor2135ac Firmware<3.9.6
Draytek Vigor2135ac Firmware>=4.0.0<4.2.4
Draytek Vigor2135ac
Draytek Vigor2135ax Firmware<3.9.6
Draytek Vigor2135ax Firmware>=4.0.0<4.2.4
Draytek Vigor2135ax
Draytek Vigor2135fvac Firmware<3.9.6
Draytek Vigor2135fvac Firmware>=4.0.0<4.2.4
Draytek Vigor2135fvac
Draytek Vigor2135vac Firmware<3.9.6
Draytek Vigor2135vac Firmware>=4.0.0<4.2.4
Draytek Vigor2135vac
Draytek Vigor2866ax Firmware<3.9.6
Draytek Vigor2866ax Firmware>=4.0.0<4.2.4
Draytek Vigor2866ax
Draytek Vigor2866ac Firmware<3.9.6
Draytek Vigor2866ac Firmware>=4.0.0<4.2.4
Draytek Vigor2866ac
Draytek Vigor2866vac Firmware<3.9.6
Draytek Vigor2866vac Firmware>=4.0.0<4.2.4
Draytek Vigor2866vac
Draytek Vigor2866l Firmware<3.9.6
Draytek Vigor2866l Firmware>=4.0.0<4.2.4
Draytek Vigor2866l
Draytek Vigor2866lac Firmware<3.9.6
Draytek Vigor2866lac Firmware>=4.0.0<4.2.4
Draytek Vigor2866lac
Draytek Vigor2865ac Firmware<3.9.6
Draytek Vigor2865ac Firmware>=4.0.0<4.2.4
Draytek Vigor2865ac
Draytek Vigor2865ax Firmware<3.9.6
Draytek Vigor2865ax Firmware>=4.0.0<4.2.4
Draytek Vigor2865ax
Draytek Vigor2865vac Firmware<3.9.6
Draytek Vigor2865vac Firmware>=4.0.0<4.2.4
Draytek Vigor2865vac
Draytek Vigor2865l Firmware<3.9.6
Draytek Vigor2865l Firmware>=4.0.0<4.2.4
Draytek Vigor2865l
Draytek Vigor2865lac Firmware<3.9.6
Draytek Vigor2865lac Firmware>=4.0.0<4.2.4
Draytek Vigor2865lac
Draytek Vigor2862n Firmware<3.9.6
Draytek Vigor2862n Firmware>=4.0.0<4.2.4
Draytek Vigor2862n
Draytek Vigor2862ac Firmware<3.9.6
Draytek Vigor2862ac Firmware>=4.0.0<4.2.4
Draytek Vigor2862ac
Draytek Vigor2862vac Firmware<3.9.6
Draytek Vigor2862vac Firmware>=4.0.0<4.2.4
Draytek Vigor2862vac
Draytek Vigor2862b Firmware<3.9.6
Draytek Vigor2862b Firmware>=4.0.0<4.2.4
Draytek Vigor2862b
Draytek Vigor2862bn Firmware<3.9.6
Draytek Vigor2862bn Firmware>=4.0.0<4.2.4
Draytek Vigor2862bn
Draytek Vigor2862l Firmware<3.9.6
Draytek Vigor2862l Firmware>=4.0.0<4.2.4
Draytek Vigor2862l
Draytek Vigor2862lac Firmware<3.9.6
Draytek Vigor2862lac Firmware>=4.0.0<4.2.4
Draytek Vigor2862lac
Draytek Vigor2862ln Firmware<3.9.6
Draytek Vigor2862ln Firmware>=4.0.0<4.2.4
Draytek Vigor2862ln
Draytek Vigor2832n Firmware<3.9.6
Draytek Vigor2832n Firmware>=4.0.0<4.2.4
Draytek Vigor2832n
Draytek Vigor2927ax Firmware<3.9.6
Draytek Vigor2927ax Firmware>=4.0.0<4.2.4
Draytek Vigor2927ax
Draytek Vigor2927ac Firmware<3.9.6
Draytek Vigor2927ac Firmware>=4.0.0<4.2.4
Draytek Vigor2927ac
Draytek Vigor2927vac Firmware<3.9.6
Draytek Vigor2927vac Firmware>=4.0.0<4.2.4
Draytek Vigor2927vac
Draytek Vigor2927f Firmware<3.9.6
Draytek Vigor2927f Firmware>=4.0.0<4.2.4
Draytek Vigor2927f
Draytek Vigor2927l Firmware<3.9.6
Draytek Vigor2927l Firmware>=4.0.0<4.2.4
Draytek Vigor2927l
Draytek Vigor2927lac Firmware<3.9.6
Draytek Vigor2927lac Firmware>=4.0.0<4.2.4
Draytek Vigor2927lac
Draytek Vigor2926 Plus Firmware<3.9.6
Draytek Vigor2926 Plus Firmware>=4.0.0<4.2.4
Draytek Vigor2926 Plus
Draytek Vigor2962 Firmware<3.9.6
Draytek Vigor2962 Firmware>=4.0.0<4.2.4
Draytek Vigor2962
Draytek Vigor1000b Firmware<3.9.6
Draytek Vigor1000b Firmware>=4.0.0<4.2.4
Draytek Vigor1000b
Draytek Vigor3910 Firmware<3.9.6
Draytek Vigor3910 Firmware>=4.0.0<4.2.4
DrayTek Vigor3910
Draytek Vigor165 Firmware<3.9.6
Draytek Vigor165 Firmware>=4.0.0<4.2.4
Draytek Vigor165
Draytek Vigor166 Firmware<3.9.6
Draytek Vigor166 Firmware>=4.0.0<4.2.4
Draytek Vigor166
Draytek Vigor130 Firmware<3.9.6
Draytek Vigor130 Firmware>=4.0.0<4.2.4
Draytek Vigor130
Draytek Vigor167 Firmware<3.9.6
Draytek Vigor167 Firmware>=4.0.0<4.2.4
DrayTek Vigor167

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203