Security Advisory 29 July 2026

Security Advisory 29 July 2026

Security Advisory: IKEv2/IPsec Investigation

Release Date: 29 July 2026

DrayTek is investigating reports that some older Vigor router models may be vulnerable to an IKEv2/IPsec attack that can cause unexpected device reboots. The issue appears to affect legacy platforms, including 2120 / 2133 / 2860 / 2912 / 2925 / 2926 / 2952(v3.x.x.x), while no impact has been identified on current-generation models at this time.

DrayTek is developing security patches for router models that remain within their supported product lifecycles and have not reached End of Life (EoL) status. Updated firmware for these router models should become available within the next few weeks.

For details on DrayTek's product lifecycle and support status, please refer to:

https://www.draytek.com/support/product-lifecycle/

Recommendations:

If you have an affected router, see the recommended actions below:

1

Disable IPsec
If IPsec VPN is not used, it is recommended that you disable this service in the router's VPN and Remote Access >> Remote Access Control Setup menu. This will reduce the attack surface until a firmware patch becomes available.

2

Capture IPsec data packets
If the issue occurs on your router, please capture IPsec/IKEv2 data packets (UDP ports 500 and 4500) and forward them to our technical support via the helpdesk. This will assist DrayTek R&D with troubleshooting, root cause analysis, and the development of firmware security updates.

3

Model Upgrade
Since this issue affects older Vigor router models, it is recommended that you upgrade to a current-generation Vigor router model, which features the latest hardware platform, security enhancements, and ongoing firmware support.