bk99.de entertain the web since 1997

Takeover possible: DrayTek routers with critical security hole

Summary

In 2022 Trellix found a critical hole (CVE-2022-32548, CVSS 10.0) in numerous DrayTek routers through which unauthenticated attackers could take over the devices. A logic error in the length check on the login page /cgi-bin/wlogin.cgi led to a buffer overflow, exploitable from the LAN or via the internet if management was reachable there. The researchers found more than 200,000 vulnerable devices on the net.

Ideas

  • A pre-authentication hole is the most dangerous class for network devices.
  • Prepared Base64 values in form fields triggered the overflow.
  • The SSL VPN service could also be an attack path.
  • A hijacked router serves as a springboard into the internal network.

Insights

  • Management interfaces reachable from the internet turn a hole into a mass threat.
  • Routers for small businesses in particular often sit unprotected at the network edge.

Facts

  • Around 30 model series were affected, from Vigor130 to Vigor3910.
  • As a workaround, DrayTek advised blocking internet access to management and switching off SSL VPN.

References

Critique

  • The long list of models helps with matching, but does not explain which devices could be managed from the internet by default.

Recommendations

  • Always block access to routers’ management interfaces from the internet.
  • Replace SSL VPN on consumer and SOHO routers with a separate, maintained VPN such as WireGuard.

Read the original article

Search the Web Archive