Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    How the Employment Rights Act 2025 empowers unions and employees, and how the games business must prepare

    Jobs Roundup: February 2026 | Testronic appoints Mike Wallen as president and main board director

    Supercell revenue declines 4% to €2.65bn in 2025

    Facebook X (Twitter) Instagram
    • Artificial Intelligence
    • Business Technology
    • Cryptocurrency
    • Gadgets
    • Gaming
    • Health
    • Software and Apps
    • Technology
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Tech AI Verse
    • Home
    • Artificial Intelligence

      Read the extended transcript: President Donald Trump interviewed by ‘NBC Nightly News’ anchor Tom Llamas

      February 6, 2026

      Stocks and bitcoin sink as investors dump software company shares

      February 4, 2026

      AI, crypto and Trump super PACs stash millions to spend on the midterms

      February 2, 2026

      To avoid accusations of AI cheating, college students are turning to AI

      January 29, 2026

      ChatGPT can embrace authoritarian ideas after just one prompt, researchers say

      January 24, 2026
    • Business

      New VoidLink malware framework targets Linux cloud servers

      January 14, 2026

      Nvidia Rubin’s rack-scale encryption signals a turning point for enterprise AI security

      January 13, 2026

      How KPMG is redefining the future of SAP consulting on a global scale

      January 10, 2026

      Top 10 cloud computing stories of 2025

      December 22, 2025

      Saudia Arabia’s STC commits to five-year network upgrade programme with Ericsson

      December 18, 2025
    • Crypto

      HBAR Shorts Face $5 Million Risk if Price Breaks Key Level

      February 10, 2026

      Ethereum Holds $2,000 Support — Accumulation Keeps Recovery Hopes Alive

      February 10, 2026

      Miami Mansion Listed for 700 BTC as California Billionaire Tax Sparks Relocations

      February 10, 2026

      Solana Drops to 2-Year Lows — History Suggests a Bounce Toward $100 is Incoming

      February 10, 2026

      Bitget Cuts Stock Perps Fees to Zero for Makers Ahead of Earnings Season, Expanding Access Across Markets

      February 10, 2026
    • Technology

      OpenAI upgrades its Responses API to support agent skills and a complete terminal shell

      February 11, 2026

      ‘Observational memory’ cuts AI agent costs 10x and outscores RAG on long-context benchmarks

      February 11, 2026

      Is agentic AI ready to reshape Global Business Services?

      February 11, 2026

      OpenAI’s new Codex app hits 1M+ downloads in first week — but limits may be coming to free and Go users

      February 11, 2026

      Nvidia releases DreamDojo, a robot ‘world model’ trained on 44,000 hours of human video

      February 11, 2026
    • Others
      • Gadgets
      • Gaming
      • Health
      • Software and Apps
    Check BMI
    Tech AI Verse
    You are at:Home»Technology»DrayTek warns of remote code execution bug in Vigor routers
    Technology

    DrayTek warns of remote code execution bug in Vigor routers

    TechAiVerseBy TechAiVerseOctober 3, 2025No Comments3 Mins Read0 Views
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Reddit
    DrayTek warns of remote code execution bug in Vigor routers
    Share
    Facebook Twitter LinkedIn Pinterest WhatsApp Email

    DrayTek warns of remote code execution bug in Vigor routers

    Networking hardware maker DrayTek released an advisory to warn about a security vulnerability in several Vigor router models that could allow remote, unauthenticated actors to execute perform arbitrary code.

    The flaw, tracked identified as CVE-2025-10547, was reported to the vendor on July 22 by ChapsVision security researcher Pierre-Yves Maes.

    “The vulnerability can be triggered when unauthenticated remote attackers send crafted HTTP or HTTPS requests to the device’s Web User Interface (WebUI),” reads DrayTek’s security advisory.

    “Successful exploitation may cause memory corruption and a system crash, with the potential in certain circumstances could allow remote code execution.”

    DrayTek noted that WAN exposure can be reduced by disabling remote WebUI/SSL VPN access or restricting it with ACLs/VLANs. However, the WebUI remains reachable over LAN, exposed to local attackers.

    Maes told BleepingComputer that the root cause for CVE-2025-10547 is an uninitialized stack value that can be leveraged to cause the free() function to operate on arbitrary memory locations, also known as arbitrary free(), to achieve remote code execution (RCE).

    The researcher successfully tested his findings by creating an exploit and running it on DrayTek devices.

    DrayTek’s security bulletin does not mention ongoing exploitation, but it is recommended to mitigate the risk.

    Below are the models impacted by CVE-2025-10547, and the recommended firmware version upgrade target to mitigate the flaw:

    • Vigor1000B, Vigor2962, Vigor3910/3912 → 4.4.3.6 or later (some models 4.4.5.1)
    • Vigor2135, Vigor2763/2765/2766, Vigor2865/2866 Series (incl. LTE & 5G), Vigor2927 Series (incl. LTE & 5G) → 4.5.1 or later
    • Vigor2915 Series → 4.4.6.1 or later
    • Vigor2862/2926 Series (incl. LTE) → 3.9.9.12 or later
    • Vigor2952/2952P, Vigor3220 → 3.9.8.8 or later
    • Vigor2860/2925 Series (incl. LTE) → 3.9.8.6 or later
    • Vigor2133/2762/2832 Series → 3.9.9.4 or later
    • Vigor2620 Series → 3.9.9.5 or later
    • VigorLTE 200n → 3.9.9.3 or later

    DrayTek routers, especially Vigor models, are very common in prosumer and small to medium business (SMB) environments. The list of impacted models covers a broad range, from flagship models to older routers used in DLS/telecom environments.

    System administrators are recommended to apply the available firmware security updates as soon as possible. Maes says he will disclose the full technical details for CVE-2025-10547 tomorrow.

    The Security Validation Event of the Year: The Picus BAS Summit

    Join the Breach and Attack Simulation Summit and experience the future of security validation. Hear from top experts and see how AI-powered BAS is transforming breach and attack simulation.

    Don’t miss the event that will shape the future of your security strategy

    Share. Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Telegram Email
    Previous ArticleHackerOne paid $81 million in bug bounties over the past year
    Next Article Microsoft Outlook stops displaying inline SVG images used in attacks
    TechAiVerse
    • Website

    Jonathan is a tech enthusiast and the mind behind Tech AI Verse. With a passion for artificial intelligence, consumer tech, and emerging innovations, he deliver clear, insightful content to keep readers informed. From cutting-edge gadgets to AI advancements and cryptocurrency trends, Jonathan breaks down complex topics to make technology accessible to all.

    Related Posts

    OpenAI upgrades its Responses API to support agent skills and a complete terminal shell

    February 11, 2026

    ‘Observational memory’ cuts AI agent costs 10x and outscores RAG on long-context benchmarks

    February 11, 2026

    Is agentic AI ready to reshape Global Business Services?

    February 11, 2026
    Leave A Reply Cancel Reply

    Top Posts

    Ping, You’ve Got Whale: AI detection system alerts ships of whales in their path

    April 22, 2025664 Views

    Lumo vs. Duck AI: Which AI is Better for Your Privacy?

    July 31, 2025250 Views

    6.7 Cummins Lifter Failure: What Years Are Affected (And Possible Fixes)

    April 14, 2025151 Views

    6 Best MagSafe Phone Grips (2025), Tested and Reviewed

    April 6, 2025111 Views
    Don't Miss
    Gaming February 11, 2026

    How the Employment Rights Act 2025 empowers unions and employees, and how the games business must prepare

    How the Employment Rights Act 2025 empowers unions and employees, and how the games business…

    Jobs Roundup: February 2026 | Testronic appoints Mike Wallen as president and main board director

    Supercell revenue declines 4% to €2.65bn in 2025

    Riot Games downsizes 2XKO team, about 80 employees affected

    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    About Us
    About Us

    Welcome to Tech AI Verse, your go-to destination for everything technology! We bring you the latest news, trends, and insights from the ever-evolving world of tech. Our coverage spans across global technology industry updates, artificial intelligence advancements, machine learning ethics, and automation innovations. Stay connected with us as we explore the limitless possibilities of technology!

    Facebook X (Twitter) Pinterest YouTube WhatsApp
    Our Picks

    How the Employment Rights Act 2025 empowers unions and employees, and how the games business must prepare

    February 11, 20263 Views

    Jobs Roundup: February 2026 | Testronic appoints Mike Wallen as president and main board director

    February 11, 20262 Views

    Supercell revenue declines 4% to €2.65bn in 2025

    February 11, 20263 Views
    Most Popular

    7 Best Kids Bikes (2025): Mountain, Balance, Pedal, Coaster

    March 13, 20250 Views

    VTOMAN FlashSpeed 1500: Plenty Of Power For All Your Gear

    March 13, 20250 Views

    This new Roomba finally solves the big problem I have with robot vacuums

    March 13, 20250 Views
    © 2026 TechAiVerse. Designed by Divya Tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms & Conditions

    Type above and press Enter to search. Press Esc to cancel.