Draytek firewall users, Update firewalls immediately!

Status
Not open for further replies.

BrenttG

Platinum Partner
Advanced Certified
Joined
Nov 17, 2017
Messages
912
Reaction score
586
Ill keep it short and sweet, you can review the PDF im attaching for more info, i know a lot of people on here swear by draytek, or at least use them a lot in 3CX deployments, i personally despise them, but have a few in deployment due to my predecessor not realizing their lack of quality in design and firmware, regardless of those beliefs tho, there are several new critical firmware security vulnerabilities that have been discovered and released, you need to update them immediately.

Attackers can capture network traffic, take control over the devices SSH, create further backdoors, and even manage system accounts on the firewall itself, essentially they can take full control of the device, and use it to pivot your entire network.

There is also confirmation within the documentation, THESE HAVE BEEN SEEN EXPLOITED IN THE WILD! Were not talking about theoretical's in this report, its in the wild already being exploited.

See attached documentation provided to myself from the FBI Infragard.

REFERENCES:
DrayTek:

https://www.draytek.com/about/secur...anagement-page-vulnerability-(cve-2020-8515)/

360 Netlab:
https://blog.netlab.360.com/two-zero-days-are-targeting-draytek-broadband-cpe-devices-en/

CVE:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8515
 

Attachments

Last edited:
Status
Not open for further replies.

Forum statistics

Threads
111,941
Messages
589,855
Members
164,832
Latest member
Boblatino