Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-33778


Draytek Vigor Routers firmware versions below 3.9.6/4.2.4, Access Points firmware versions below v1.4.0, Switches firmware versions below 2.6.7, and Myvigor firmware versions below 2.3.2 were discovered to use hardcoded encryption keys which allows attackers to bind any affected device to their own account. Attackers are then able to create WCF and DrayDDNS licenses and synchronize them from the website.


Security Impact Summary

This vulnerability carries a CRITICAL severity rating with a CVSS v3.1 score of 9.8, indicating it can be exploited remotely over the network with relatively low complexity without requiring user interaction and does not require pre-existing privileges . The vulnerability impacts confidentiality (data exposure), integrity (unauthorized modifications), and availability (service disruption) for affected systems. Impacting 143 products from draytek, from draytek, from draytek and 140 others, organizations running these solutions should prioritize assessment and patching.

Historical Context

Reported in 2023, this vulnerability emerged during an era marked by increased sophistication in supply chain attacks, cloud infrastructure vulnerabilities, and software-as-a-service (SaaS) security challenges. Security practices during this period emphasized zero-trust architectures, container security, and API protection.


Published

2023-06-01T04:15:10.313

Last Modified

2025-01-09T18:15:26.790

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

Weaknesses
  • Type: Primary
    CWE-798
  • Type: Secondary
    CWE-798

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application draytek myvigor < 2.3.2 Yes
Operating System draytek vigorswitch_pq2200xb_firmware < 2.6.7 Yes
Hardware draytek vigorswitch_pq2200xb - No
Operating System draytek vigorswitch_pq2121x_firmware < 2.6.7 Yes
Hardware draytek vigorswitch_pq2121x - No
Operating System draytek vigorswitch_p2540xs_firmware < 2.6.7 Yes
Hardware draytek vigorswitch_p2540xs - No
Operating System draytek vigorswitch_p2280x_firmware < 2.6.7 Yes
Hardware draytek vigorswitch_p2280x - No
Operating System draytek vigorswitch_p2100_firmware < 2.6.7 Yes
Hardware draytek vigorswitch_p2100 - No
Operating System draytek vigorswitch_q2200x_firmware < 2.6.7 Yes
Hardware draytek vigorswitch_q2200x - No
Operating System draytek vigorswitch_q2121x_firmware < 2.6.7 Yes
Hardware draytek vigorswitch_q2121x - No
Operating System draytek vigorswitch_g2540xs_firmware < 2.6.7 Yes
Hardware draytek vigorswitch_g2540xs - No
Operating System draytek vigorswitch_g2280x_firmware < 2.6.7 Yes
Hardware draytek vigorswitch_g2280x - No
Operating System draytek vigorswitch_g2121_firmware < 2.6.7 Yes
Hardware draytek vigorswitch_g2121 - No
Operating System draytek vigorswitch_g2100_firmware < 2.6.7 Yes
Hardware draytek vigorswitch_g2100 - No
Operating System draytek vigorswitch_fx2120_firmware < 2.6.7 Yes
Hardware draytek vigorswitch_fx2120 - No
Operating System draytek vigorswitch_p1282_firmware < 2.6.7 Yes
Hardware draytek vigorswitch_p1282 - No
Operating System draytek vigorswitch_g1282_firmware < 2.6.7 Yes
Hardware draytek vigorswitch_g1282 - No
Operating System draytek vigorswitch_g1085_firmware < 2.6.7 Yes
Hardware draytek vigorswitch_g1085 - No
Operating System draytek vigorswitch_g1080_firmware < 2.6.7 Yes
Hardware draytek vigorswitch_g1080 - No
Operating System draytek vigorap_903_firmware < 1.4.0 Yes
Hardware draytek vigorap_903 - No
Operating System draytek vigorap_912c_firmware < 1.4.0 Yes
Hardware draytek vigorap_912c - No
Operating System draytek vigorap_918r_firmware < 1.4.0 Yes
Hardware draytek vigorap_918r - No
Operating System draytek vigorap_1060c_firmware < 1.4.0 Yes
Hardware draytek vigorap_1060c - No
Operating System draytek vigorap_906_firmware < 1.4.0 Yes
Hardware draytek vigorap_906 - No
Operating System draytek vigorap_960c_firmware < 1.4.0 Yes
Hardware draytek vigorap_960c - No
Operating System draytek vigorap_1000c_firmware < 1.4.0 Yes
Hardware draytek vigorap_1000c - No
Operating System draytek vigor2766ac_firmware < 3.9.6 Yes
Operating System draytek vigor2766ac_firmware < 4.2.4 Yes
Hardware draytek vigor2766ac - No
Operating System draytek vigor2766ax_firmware < 3.9.6 Yes
Operating System draytek vigor2766ax_firmware < 4.2.4 Yes
Hardware draytek vigor2766ax - No
Operating System draytek vigor2766vac_firmware < 3.9.6 Yes
Operating System draytek vigor2766vac_firmware < 4.2.4 Yes
Hardware draytek vigor2766vac - No
Operating System draytek vigor2765ax_firmware < 3.9.6 Yes
Operating System draytek vigor2765ax_firmware < 4.2.4 Yes
Hardware draytek vigor2765ax - No
Operating System draytek vigor2765vac_firmware < 3.9.6 Yes
Operating System draytek vigor2765vac_firmware < 4.2.4 Yes
Hardware draytek vigor2765vac - No
Operating System draytek vigor2765ac_firmware < 3.9.6 Yes
Operating System draytek vigor2765ac_firmware < 4.2.4 Yes
Hardware draytek vigor2765ac - No
Operating System draytek vigor2763ac_firmware < 3.9.6 Yes
Operating System draytek vigor2763ac_firmware < 4.2.4 Yes
Hardware draytek vigor2763ac - No
Operating System draytek vigor2620l_firmware < 3.9.6 Yes
Operating System draytek vigor2620l_firmware < 4.2.4 Yes
Hardware draytek vigor2620l - No
Operating System draytek vigor2620ln_firmware < 3.9.6 Yes
Operating System draytek vigor2620ln_firmware < 4.2.4 Yes
Hardware draytek vigor2620ln - No
Operating System draytek vigorlte_200n_firmware < 3.9.6 Yes
Operating System draytek vigorlte_200n_firmware < 4.2.4 Yes
Hardware draytek vigorlte_200n - No
Operating System draytek vigor2915ac_firmware < 3.9.6 Yes
Operating System draytek vigor2915ac_firmware < 4.2.4 Yes
Hardware draytek vigor2915ac - No
Operating System draytek vigor2135ac_firmware < 3.9.6 Yes
Operating System draytek vigor2135ac_firmware < 4.2.4 Yes
Hardware draytek vigor2135ac - No
Operating System draytek vigor2135ax_firmware < 3.9.6 Yes
Operating System draytek vigor2135ax_firmware < 4.2.4 Yes
Hardware draytek vigor2135ax - No
Operating System draytek vigor2135fvac_firmware < 3.9.6 Yes
Operating System draytek vigor2135fvac_firmware < 4.2.4 Yes
Hardware draytek vigor2135fvac - No
Operating System draytek vigor2135vac_firmware < 3.9.6 Yes
Operating System draytek vigor2135vac_firmware < 4.2.4 Yes
Hardware draytek vigor2135vac - No
Operating System draytek vigor2866ax_firmware < 3.9.6 Yes
Operating System draytek vigor2866ax_firmware < 4.2.4 Yes
Hardware draytek vigor2866ax - No
Operating System draytek vigor2866ac_firmware < 3.9.6 Yes
Operating System draytek vigor2866ac_firmware < 4.2.4 Yes
Hardware draytek vigor2866ac - No
Operating System draytek vigor2866vac_firmware < 3.9.6 Yes
Operating System draytek vigor2866vac_firmware < 4.2.4 Yes
Hardware draytek vigor2866vac - No
Operating System draytek vigor2866l_firmware < 3.9.6 Yes
Operating System draytek vigor2866l_firmware < 4.2.4 Yes
Hardware draytek vigor2866l - No
Operating System draytek vigor2866lac_firmware < 3.9.6 Yes
Operating System draytek vigor2866lac_firmware < 4.2.4 Yes
Hardware draytek vigor2866lac - No
Operating System draytek vigor2865ac_firmware < 3.9.6 Yes
Operating System draytek vigor2865ac_firmware < 4.2.4 Yes
Hardware draytek vigor2865ac - No
Operating System draytek vigor2865ax_firmware < 3.9.6 Yes
Operating System draytek vigor2865ax_firmware < 4.2.4 Yes
Hardware draytek vigor2865ax - No
Operating System draytek vigor2865vac_firmware < 3.9.6 Yes
Operating System draytek vigor2865vac_firmware < 4.2.4 Yes
Hardware draytek vigor2865vac - No
Operating System draytek vigor2865l_firmware < 3.9.6 Yes
Operating System draytek vigor2865l_firmware < 4.2.4 Yes
Hardware draytek vigor2865l - No
Operating System draytek vigor2865lac_firmware < 3.9.6 Yes
Operating System draytek vigor2865lac_firmware < 4.2.4 Yes
Hardware draytek vigor2865lac - No
Operating System draytek vigor2862n_firmware < 3.9.6 Yes
Operating System draytek vigor2862n_firmware < 4.2.4 Yes
Hardware draytek vigor2862n - No
Operating System draytek vigor2862ac_firmware < 3.9.6 Yes
Operating System draytek vigor2862ac_firmware < 4.2.4 Yes
Hardware draytek vigor2862ac - No
Operating System draytek vigor2862vac_firmware < 3.9.6 Yes
Operating System draytek vigor2862vac_firmware < 4.2.4 Yes
Hardware draytek vigor2862vac - No
Operating System draytek vigor2862b_firmware < 3.9.6 Yes
Operating System draytek vigor2862b_firmware < 4.2.4 Yes
Hardware draytek vigor2862b - No
Operating System draytek vigor2862bn_firmware < 3.9.6 Yes
Operating System draytek vigor2862bn_firmware < 4.2.4 Yes
Hardware draytek vigor2862bn - No
Operating System draytek vigor2862l_firmware < 3.9.6 Yes
Operating System draytek vigor2862l_firmware < 4.2.4 Yes
Hardware draytek vigor2862l - No
Operating System draytek vigor2862lac_firmware < 3.9.6 Yes
Operating System draytek vigor2862lac_firmware < 4.2.4 Yes
Hardware draytek vigor2862lac - No
Operating System draytek vigor2862ln_firmware < 3.9.6 Yes
Operating System draytek vigor2862ln_firmware < 4.2.4 Yes
Hardware draytek vigor2862ln - No
Operating System draytek vigor2832n_firmware < 3.9.6 Yes
Operating System draytek vigor2832n_firmware < 4.2.4 Yes
Hardware draytek vigor2832n - No
Operating System draytek vigor2927ax_firmware < 3.9.6 Yes
Operating System draytek vigor2927ax_firmware < 4.2.4 Yes
Hardware draytek vigor2927ax - No
Operating System draytek vigor2927ac_firmware < 3.9.6 Yes
Operating System draytek vigor2927ac_firmware < 4.2.4 Yes
Hardware draytek vigor2927ac - No
Operating System draytek vigor2927vac_firmware < 3.9.6 Yes
Operating System draytek vigor2927vac_firmware < 4.2.4 Yes
Hardware draytek vigor2927vac - No
Operating System draytek vigor2927f_firmware < 3.9.6 Yes
Operating System draytek vigor2927f_firmware < 4.2.4 Yes
Hardware draytek vigor2927f - No
Operating System draytek vigor2927l_firmware < 3.9.6 Yes
Operating System draytek vigor2927l_firmware < 4.2.4 Yes
Hardware draytek vigor2927l - No
Operating System draytek vigor2927lac_firmware < 3.9.6 Yes
Operating System draytek vigor2927lac_firmware < 4.2.4 Yes
Hardware draytek vigor2927lac - No
Operating System draytek vigor2926_plus_firmware < 3.9.6 Yes
Operating System draytek vigor2926_plus_firmware < 4.2.4 Yes
Hardware draytek vigor2926_plus - No
Operating System draytek vigor2962_firmware < 3.9.6 Yes
Operating System draytek vigor2962_firmware < 4.2.4 Yes
Hardware draytek vigor2962 - No
Operating System draytek vigor1000b_firmware < 3.9.6 Yes
Operating System draytek vigor1000b_firmware < 4.2.4 Yes
Hardware draytek vigor1000b - No
Operating System draytek vigor3910_firmware < 3.9.6 Yes
Operating System draytek vigor3910_firmware < 4.2.4 Yes
Hardware draytek vigor3910 - No
Operating System draytek vigor165_firmware < 3.9.6 Yes
Operating System draytek vigor165_firmware < 4.2.4 Yes
Hardware draytek vigor165 - No
Operating System draytek vigor166_firmware < 3.9.6 Yes
Operating System draytek vigor166_firmware < 4.2.4 Yes
Hardware draytek vigor166 - No
Operating System draytek vigor130_firmware < 3.9.6 Yes
Operating System draytek vigor130_firmware < 4.2.4 Yes
Hardware draytek vigor130 - No
Operating System draytek vigor167_firmware < 3.9.6 Yes
Operating System draytek vigor167_firmware < 4.2.4 Yes
Hardware draytek vigor167 - No

References

How SecUtils Interprets This CVE

SecUtils normalizes and enriches National Vulnerability Database (NVD) records by standardizing vendor and product identifiers, aggregating vulnerability metadata from both NVD and MITRE sources, and providing structured context for security teams. For draytek's affected products, we extract Common Platform Enumeration (CPE) data, Common Weakness Enumeration (CWE) classifications, CVSS severity metrics, and reference data to enable rapid vulnerability prioritization and asset correlation. This record contains no exploit code, proof-of-concept instructions, or attack methodologies—only defensive intelligence necessary for patch management, risk assessment, and security operations.