Takeover possible: DrayTek routers with critical security hole
Summary
In 2022 Trellix found a critical hole (CVE-2022-32548, CVSS 10.0) in numerous DrayTek routers through which unauthenticated attackers could take over the devices. A logic error in the length check on the login page /cgi-bin/wlogin.cgi led to a buffer overflow, exploitable from the LAN or via the internet if management was reachable there. The researchers found more than 200,000 vulnerable devices on the net.
Ideas
- A pre-authentication hole is the most dangerous class for network devices.
- Prepared Base64 values in form fields triggered the overflow.
- The SSL VPN service could also be an attack path.
- A hijacked router serves as a springboard into the internal network.
Insights
- Management interfaces reachable from the internet turn a hole into a mass threat.
- Routers for small businesses in particular often sit unprotected at the network edge.
Facts
- Around 30 model series were affected, from Vigor130 to Vigor3910.
- As a workaround, DrayTek advised blocking internet access to management and switching off SSL VPN.
References
Critique
- The long list of models helps with matching, but does not explain which devices could be managed from the internet by default.
Recommendations
- Always block access to routers’ management interfaces from the internet.
- Replace SSL VPN on consumer and SOHO routers with a separate, maintained VPN such as WireGuard.
Links to the original source and the Web Archive open in a new tab.