Weekly Update 18 May 2022

Weekly Update 18 May 2022

Security Advisory

OpenSSL vulnerability (CVE-2022-0778)

Released Date: 2022-04-27


A Denial-Of-Service Vulnerability in OpenSSL (CVE-2022-0778) has been found recently. The BN_mod_sqrt() function in OpenSSL, which is used for parsing certificates contains a bug that can cause it to go into an endless loop. This bug affects DrayTek products causing the HTTPS server for management to stop working resulting in a reboot when parsing or importing a maliciously crafted certificate. OpenSSL has released a security update to address the vulnerability. DrayTek is releasing new firmware with security updates for the OpenSSL vulnerability.

More details at: https://www.draytek.com/about/security-advisory/openssl-vulnerability-(cve-2022-0778)/

 

Latest Updated firmware versions are listed below in the latest firmware section.

 

Latest Videos

Configuring theDrayTek Vigor167 for PPPoE

In this video we go through the steps required to set up the Vigor167 router to connect to VDSL2 using PPPoE with a username and password.



Click here to watch the video.

 

DrayTek OnlineWorkshop - DrayTek VPN Solutions

This is a recording of an online DrayTek workshop held recently. The topic for this workshop is DrayTek VPN solutions, where we looked at the types of VPN tunnels and configuration options available in DrayTek routers.

The workshop consists of background theory & videos as well as hands-on demonstrations of the practical exercises covered in the workshop manual.

If you require a copy of the workshop manual, please contact us at  support@draytek.com.au



Click here to watch the recording.

 

Latest Software

Syslog Utility V4.7.0

New Features

·         Add the Wireless and Mesh tabs for wireless router.

Improvements

·               -  Syslog Format with Syslog Utility

·              -   Fixed: Issue related to Syslog Utility on Windows XP SP3

·               -  Fixed: Displaying Syslog Utility via Windows10

Click  here to download the app.

Latest Firmware

VigorSwitch G2540x / P2540x V2.7.2

New Features

·               -  Add the function of Dying gasp.

·               -  Add the new algorithm (IP only or Source Port only) for LAG.

Improvements

·              -   Change the fiber ports media type default setting as Auto.

·               -  Change Port Bandwidth Utilization page’s colors display, let it match Dashboard.

·               -  Fixed: RADIUS settings lost on reboot.

·              -   Fixed: Broken status information of the SFP optical module.

·              -   Fixed: Unable to store the VLAN interface uplink TPID setting.

Click here to download the G2540x firmware.

Click here to download the P2540x firmware.

 

******************************

Firmware is available for the following routers with the following security improvements:

·         Improve Web GUI Security.

·         Improve the OpenSSL security (CVE-2022-0778)

VigorNIC 132 V3.8.5

Click here to download the firmware.

 

Vigor130 V3.8.5

Click here to download the firmware.

 

Vigor167 V5.1.1

Click here to download the firmware.

 

Vigor2620 LTE V3.9.8.1

Click here to download the firmware.

 

VigorLTE 200n V3.9.8.1

Click here to download the firmware.


To subscribe to our regular news updates, click on “Subscribe” on this page or login into your i-helpdesk account and enable the “Subscribe” option.

 



    • Related Articles

    • Weekly Update 4 May 2022

      Security Advisory OpenSSL vulnerability (CVE-2022-0778) Released Date: 2022-04-27 A Denial-Of-Service Vulnerability in OpenSSL (CVE-2022-0778) has been found recently. The BN_mod_sqrt() function in OpenSSL, which is used for parsing certificates ...
    • Weekly Update 6 May 2020

      Upcoming Webinar DrayTekVPN solutions (Part 1) – Introduction to VPN Tuesday 12th May 2020 at 10:00 am (AEST) Duration 30 Minutes  You are invited to attend our next webinar DrayTek VPN Solutions - Part 1 – Introduction to VPN. This is the first of a ...
    • Weekly Update 2 December 2021

      Latest Firmware Vigor2832 V3.9.5 Improvement ·              -   Fixed: Failure to do network connection with WAN3. ·              -  Fixed: Default route missed after disabling a static route. ·              -  Fixed: Firmware upgrade via VigorACS ...
    • Weekly Update 14 April 2021

      Latest Application Notes LAN Forward All DNS Queries to a Private DNS Server The latest firmware for DrayTek routers now includes an option to forward all DNS requests to a private DNS server regardless of the setting in the client PC. This ...
    • Weekly Update 18 April 2023

      Latest Videos How to use mOTP for SSL VPN on iPhone This video shows how to quickly set up an SSL VPN tunnel using SmartVPN for an iPhone, and adding mOTP for 2FA authentication. It also shows how to use the internal mOTP generator that has been ...