Technical Discussion
  >> Home Networking, Internet Connection Sharing, etc.


Register (or login) on our website and you will not see this ad.


  Print Thread
Standard User trolleybus
(fountain of knowledge) Mon 21-Oct-24 11:15:45
Print Post

Critical Security Alert: Multiple Vulnerabilities in DrayTek


[link to this post]
 
Received this email this morning:
From: [email protected] <[email protected]>
Sent: 21 October 2024 09:16
With the subject as per the title

The odd thing is that when I go onto DrayTek's resource centre, I find I already have the latest available firmware which has bee installed for some time now.

The email certainly looks genuine enough, but oddly timed. Thoughts on this anyone?
Standard User GonePostal
(experienced) Mon 21-Oct-24 13:54:22
Print Post

Re: Critical Security Alert: Multiple Vulnerabilities in Dra *DELETED*


[re: trolleybus] [link to this post]
 
Post deleted by GonePostal
Standard User mrmarktigger
(member) Mon 21-Oct-24 16:49:01
Print Post

Re: Critical Security Alert: Multiple Vulnerabilities in Dra


[re: trolleybus] [link to this post]
 
I've just checked for my DrayTek Vigor2862 series amd there is a Critical – Upgrade recommended immediately, Release Date 17th October 2024.


Register (or login) on our website and you will not see this ad.

Standard User broadbandjockey
(committed) Mon 21-Oct-24 17:48:34
Print Post

Re: Critical Security Alert: Multiple Vulnerabilities in Dra


[re: trolleybus] [link to this post]
 
Well, there was this a couple of weeks ago

https://www.theregister.com/2024/10/02/draytek_route...
Standard User Colinh58
(newbie) Mon 21-Oct-24 18:16:00
Print Post

Re: Critical Security Alert: Multiple Vulnerabilities in Dra


[re: trolleybus] [link to this post]
 
Just checked mine for the 3912, but that appears to be up to date
There are a lot of recent updates for the more older routers it would appear though

EE 1.8Gb
Standard User Adduxi
(member) Mon 21-Oct-24 18:20:32
Print Post

Re: Critical Security Alert: Multiple Vulnerabilities in Dra


[re: trolleybus] [link to this post]
 
The vulnerabilities were from June 24, and out of the 24 routers listed, only one has not had an updated firmware released as yet, the Vigor 1000B which is forthcoming. I have checked mine and it already had the latest firmware applied. I do however check these things as a matter of course so was already ahead of this email warning.
Standard User Andrue
(eat-sleep-adslguide) Mon 21-Oct-24 20:31:42
Print Post

Re: Critical Security Alert: Multiple Vulnerabilities in Dra


[re: trolleybus] [link to this post]
 
Well thank you for that experience smile

So that's broken my mail server's IPv6 support. I've managed to get it back to connecting locally but it seems like external unsolicited packets are being blocked.

---
Andrue Cope
Brackley, UK

Edited by Andrue (Mon 21-Oct-24 20:36:30)

  Print Thread

Jump to