DrayTek Weekly Updates 21 July 2026

DrayTek Weekly Updates 21 July 2026

Security Advisory

Multiple Remote Code Execution and Buffer Overflow Vulnerabilities

 

DrayTek has released updated firmware for a range of VigorSwitch products found to be vulnerable to Buffer Overflow and OS Command Injection attacks. Although there have been no reported cases of this exploit in the field, it is recommended to update your VigorSwitch to the latest patched firmware version.

 

More details are available in the security advisory notice on the DrayTek website.



Click here for more details.

 

 

Latest Videos

QoS Setup on DrayTek Routers (DrayOS 4 & 5)


Latest Firmware

Vigor2135 V4.5.3.1

Improvements

·         Fixed: Router reboots repeatedly after the firmware upgrade

·         Fixed: Router randomly reboots multiple times a day due to attacks

·         Fixed: Firmware upgrade through VigorACS failed under certain conditions.

 

 Click here to download the firmware.

 

Vigor2136 V5.3.9

New Features

·         Support Threat Protection - Sentry, our new license-based Cybersecurity solution

·         Support 802.3x flow control via CLI commands

·         Support port-based bridging, including proper handling of tagged traffic

Improvements

·         Show State and Carrier in the IP Lookup Whois information

·         Improve the boot process for network interface initialisation

·         Fixed: Let's Encrypt syslog entries were classified as LAN type

·         Fixed: Router accepted unencrypted L2TP traffic on UDP port 1701

·         Fixed: Incorrect NAT on the VPN interface caused asymmetric OpenVPN connectivity

·         Fixed: WireGuard IPv6 VPN frequently disconnected and reconnected when the peer connected using a domain name

 

 Click here to download the firmware.

 

 

Vigor2765 V4.5.3.1

Improvements

·         Fixed: Router reboots repeatedly after the firmware upgrade

·         Fixed: Router randomly reboots multiple times a day due to attacks

·         Fixed: Firmware upgrade through VigorACS failed under certain conditions.

 

 Click here to download the firmware

 

 

Vigor2766 V4.5.3.1

Improvements

·         Fixed: Router reboots repeatedly after the firmware upgrade

·         Fixed: Router randomly reboots multiple times a day due to attacks

·         Fixed: Firmware upgrade through VigorACS failed under certain conditions.

 

 Click here to download the firmware

 

Vigor2767V5.4.1

New Features

·         Support dual-WAN Load Balance and Failover, with per-WAN Weight for Primary and Failover members

·         Support TR-369 (USP) device management via ACS

·         Add SMS Gateway to Configuration >> LTE

·         Allow specifying a hostname as the source IP for NAT and Port Forwarding rules

·         Increase the maximum number of failover members from 5 to 10

·         Support 802.3x flow control

Improvements

·         Enhance the CGI security (CVE-2026-2291, CVE-2026-4890, CVE-2026-4891, CVE-2026-4892, CVE-2026-4893, and CVE-2026-5172)

·         Reduce the LTE failover time

·         Overhaul VoIP parameter handling

·         Support email-format MyVigor username

·         Device Name configuration did not conform to the specification

 

For a complete list of improvements, refer to the release notes in the download links below.

 

Click here to download the firmware

 

Vigor C510 V5.3.9

New Features

·         Support 802.3x flow control via CLI commands

·         Support Network Scan and Preferred LTE Band selection

Improvements

·         Show State and Carrier in the IP Lookup Whois information

·         Improve the boot process for network interface initialisation

·         Fixed: Let's Encrypt syslog entries were classified as LAN type

·         Fixed: Router accepted unencrypted L2TP traffic on UDP port 1701

·         Fixed: Incorrect NAT on the VPN interface caused asymmetric OpenVPN connectivity

·         Fixed: WireGuard IPv6 VPN frequently disconnected and reconnected when the peer connected using a domain name

 

 Click here to download the firmware.

 

VigorAP 805 V5.1.1  

New Feature

·         Support TR-369 over MQTT(Message Queuing Telemetry Transport)

Improvements

 

·         Add to support to hide the Enable command

·         Fixed: Deleting External RADIUS entries failed

·         Fixed: Local service certificate settings reverted to default after a reboot

·         Fixed: An issue where the notification icon on the Main Dashboard did not display any notifications

·         Fixed: Node Device Configuration failed with error message "Field operation failed(lost, duplicated, type...etc)"

·         Fixed: TR-069 settings were not automatically saved after being pushed through the router's Wireless Virtual Controller

 

Click here to download the firmware

 

 

VigorAP 905 V5.1.1

New Feature

·         Support TR-369 over MQTT(Message Queuing Telemetry Transport)

Improvements

 

·         Add to support to hide the Enable command

·         Fixed: Deleting External RADIUS entries failed

·         Fixed: Local service certificate settings reverted to default after a reboot

·         Fixed: An issue where the notification icon on the Main Dashboard did not display any notifications

·         Fixed: Node Device Configuration failed with error message "Field operation failed(lost, duplicated, type...etc)"

·         Fixed: TR-069 settings were not automatically saved after being pushed through the router's Wireless Virtual Controller

 

Click here to download the firmware

 

VigorSwitch PQ2300xb V2.10.7

Improvements

·         Improve the CGI security (CVE-2026-52497, CVE-2026-52498, CVE-2026-52499, CVE-2026-52500, CVE-2026-52501, CVE-2026-52502 and CVE-2026-52503)

·         Incorporate security patches into OpenSSL

·         Enhance the WUI > Stacking > General Setup page to allow configuration of the Slave device's Stacking Port LAG after stacking is enabled. Add a note indicating that a reboot is required for the changes to take effect.

 

For a complete list of improvements, refer to the release notes in the download link below:

 

Click here to download the firmware

 

VigorSwitch Q2300x V2.10.7

Improvements

·         Improve the CGI security (CVE-2026-52497, CVE-2026-52498, CVE-2026-52499, CVE-2026-52500, CVE-2026-52501, CVE-2026-52502 and CVE-2026-52503)

·      Incorporate security patches into OpenSSL

·      Enhance the WUI > Stacking > General Setup page to allow configuration of the Slave device's Stacking Port LAG after stacking is enabled. Add a note indicating that a reboot is required for the changes to take effect.

 

For a complete list of improvements, refer to the release notes in the download link below:

 

Click here to download the firmware

 

 

Latest Software

Improvements
Fixed: Missing translation for WireGuard profile
Fixed: Smart VPN client system crashing unexpectedly
Fixed: Icon was incorrectly displayed when WireGuard enabled
Fixed: VPN could only connect after VPN profile was deleted and Smart VPN client was restarted

Click here to download the software.

Improvements
Fixed: An issue causing the IKEv2 EAP username/password prompt to appear two or three times when the password was not entered in the VPN profile

Click here to download the software.

Calendar Events from DrayTek HQ

DrayTek HQ frequently sends notifications about system updates, outages, security alerts, and firmware releases.

Click here for the latest news from DrayTek HQ.



To subscribe to our regular news updates, click “Subscribe” on this page or log into your i-helpdesk account and enable the “Subscribe” option.