Multiple Remote Code Execution and Buffer Overflow Vulnerabilities
DrayTek has released updated firmware for a range of VigorSwitch products found to be vulnerable to Buffer Overflow and OS Command Injection attacks. Although there have been no reported cases of this exploit in the field, it is recommended to update your VigorSwitch to the latest patched firmware version.
More
details are available in the security advisory notice on the DrayTek website.
Click here for more details.
QoS Setup on DrayTek Routers (DrayOS 4 & 5)
Improvements
· Fixed: Router reboots repeatedly after the firmware upgrade
· Fixed: Router randomly reboots multiple times a day due to attacks
· Fixed: Firmware upgrade through VigorACS failed under certain conditions.
Click here to download the firmware.
· Support Threat Protection - Sentry, our new license-based Cybersecurity solution
· Support 802.3x flow control via CLI commands
· Support port-based bridging, including proper handling of tagged traffic
Improvements
· Show State and Carrier in the IP Lookup Whois information
· Improve the boot process for network interface initialisation
· Fixed: Let's Encrypt syslog entries were classified as LAN type
· Fixed: Router accepted unencrypted L2TP traffic on UDP port 1701
· Fixed: Incorrect NAT on the VPN interface caused asymmetric OpenVPN connectivity
· Fixed: WireGuard IPv6 VPN frequently disconnected and reconnected when the peer connected using a domain name
Click here to download the firmware.
Improvements
· Fixed: Router reboots repeatedly after the firmware upgrade
· Fixed: Router randomly reboots multiple times a day due to attacks
· Fixed: Firmware upgrade through VigorACS failed under certain conditions.
Click here to download the firmware
Improvements
· Fixed: Router reboots repeatedly after the firmware upgrade
· Fixed: Router randomly reboots multiple times a day due to attacks
· Fixed: Firmware upgrade through VigorACS failed under certain conditions.
Click here to download the firmware
New Features
· Support dual-WAN Load Balance and Failover, with per-WAN Weight for Primary and Failover members
· Support TR-369 (USP) device management via ACS
· Add SMS Gateway to Configuration >> LTE
· Allow specifying a hostname as the source IP for NAT and Port Forwarding rules
· Increase the maximum number of failover members from 5 to 10
· Support 802.3x flow control
Improvements
· Reduce the LTE failover time
· Overhaul VoIP parameter handling
· Support email-format MyVigor username
· Device Name configuration did not conform to the specification
For a complete list of improvements, refer to the release notes in the download links below.
Click here to download the firmware
New Features
· Support 802.3x flow control via CLI commands
· Support Network Scan and Preferred LTE Band selection
Improvements
· Show State and Carrier in the IP Lookup Whois information
· Improve the boot process for network interface initialisation
· Fixed: Let's Encrypt syslog entries were classified as LAN type
· Fixed: Router accepted unencrypted L2TP traffic on UDP port 1701
· Fixed: Incorrect NAT on the VPN interface caused asymmetric OpenVPN connectivity
· Fixed: WireGuard IPv6 VPN frequently disconnected and reconnected when the peer connected using a domain name
Click here to download the firmware.
New Feature
· Support TR-369 over MQTT(Message Queuing Telemetry Transport)
Improvements
· Add to support to hide the Enable command
· Fixed: Deleting External RADIUS entries failed
· Fixed: Local service certificate settings reverted to default after a reboot
· Fixed: An issue where the notification icon on the Main Dashboard did not display any notifications
· Fixed: Node Device Configuration failed with error message "Field operation failed(lost, duplicated, type...etc)"
· Fixed: TR-069 settings were not automatically saved after being pushed through the router's Wireless Virtual Controller
Click here to download the firmware
New Feature
· Support TR-369 over MQTT(Message Queuing Telemetry Transport)
Improvements
· Add to support to hide the Enable command
· Fixed: Deleting External RADIUS entries failed
· Fixed: Local service certificate settings reverted to default after a reboot
· Fixed: An issue where the notification icon on the Main Dashboard did not display any notifications
· Fixed: Node Device Configuration failed with error message "Field operation failed(lost, duplicated, type...etc)"
· Fixed: TR-069 settings were not automatically saved after being pushed through the router's Wireless Virtual Controller
Click here to download the firmware
Improvements
· Improve the CGI security (CVE-2026-52497, CVE-2026-52498, CVE-2026-52499, CVE-2026-52500, CVE-2026-52501, CVE-2026-52502 and CVE-2026-52503)
· Incorporate security patches into OpenSSL
· Enhance the WUI > Stacking > General Setup page to allow configuration of the Slave device's Stacking Port LAG after stacking is enabled. Add a note indicating that a reboot is required for the changes to take effect.
For a complete list of improvements, refer to the release notes in the download link below:
Click here to download the firmware
Improvements
· Improve the CGI security (CVE-2026-52497, CVE-2026-52498, CVE-2026-52499, CVE-2026-52500, CVE-2026-52501, CVE-2026-52502 and CVE-2026-52503)
· Incorporate security patches into OpenSSL
· Enhance the WUI > Stacking > General Setup page to allow configuration of the Slave device's Stacking Port LAG after stacking is enabled. Add a note indicating that a reboot is required for the changes to take effect.
For a complete list of improvements, refer to the release notes in the download link below:
Click here to download the firmware