Weekly Update 22 April 2020

Weekly Update 22 April 2020

Security Advisory

Vigor3900 / Vigor2960 / Vigor300BStack-based buffer overflow Vulnerability (CVE-2020-10823 ~ CVE-2020-10828)

This is a critical upgrade. You should upgrade affected VigorRouters as soon as possible to firmware v1.5.1 or later to improve the functions and services security, it only affects the Vigor3900 / 2960 / 300B and is not known to affect any other DrayTek products.

Click here for more details and firmware download links.

 

Latest Application Notes

LAN

How to switch WAN2 into LAN port

  This application note shows how to configure the Vigor2862 WAN 2 port so that it becomes a LAN port.

Click here to read the application note.

VPN

L2TP over IPsec from Smart VPN toVigor Router

This application note shows how to set up Vigor Router as a VPN server for L2TP over IPsec, as well as how to use Smart VPN built-in VPN feature to establish a VPN to Vigor Router and access the Vigor Router's LAN network.

Click here to read the application note.

Firewall

WhyUDP services like IPsec, DNS, VoIP disturbed by Vigor Router?

This application note explains how enabling UDP Flood Defense in the DoS settings can affect some UDP services such as IPsec, DNS and VoIP

Click here to read the application note.

 

Latest Firmware

Vigor2862 /2862 LTE V3.9.3

Improvements

·                      -   Allow long username with 63 characters, for WAN>>Internet Access>>LTE.

·                    -  Add a restriction for welcome message, on System Maintenance >> Login Page Greeting.

·                    -  Support ACL for remote management when a 0.0.0.0 remote network VPN established.

Click here to download firmware.

 

Vigor2926 / 2926 LTE V3.9.3.1

Improvement

·                     -  Remove SSL Web VPN tunnel function.

·                     -  Allow long username with 63 characters, for WAN>>Internet Access>>LTE .

·                    -  Support IPsec Xauth and IKEv2 EAP authentication by RADIUS/LDAP/AD.

·                     -  Add a restriction for welcome message, on System Maintenance >> Login Page Greeting.

·                     -  Support ACL for remote management when a 0.0.0.0 remote network VPN established.

·                    -  Fixed: An issue of router reboots due to firmware upgrade.

·                    -  Fixed: An issue of SNMPv3 being authenticated with an incorrect password.

Click here to download firmware.

 

VigorAP 912C V1.3.4.1

Improvements

·                     -  Fixed: An issue of display error on the page of Diagnostics>>System Log.

Click here to download firmware.

VigorAP 918R/ 920R/ 1000C V1.3.3

Improvements

·                     -  Improvement for SNMP function.

·                    -  Improve the WebUI of Mesh >> Mesh Setup for Mesh Root.

·                     -  Modify Draytek AP A-Band Channel List for Australia and Thailand.

·                    -  Display SSID for 5GHz wireless station on Station List>>Clients List.

·                    -  Fixed: An issue of wireless security 802.1x.

·                     -  Fixed: A security issue of DHCP server.

·                     -  Fixed: An issue of Access Control not working when wireless security was WPA3-Personal.

Click here to download firmware.

Latest Software

VigorACS 2 V2.5.4

New Feature

·                     -  Support to manage Vigor3910, VigorAP918R, VigorAP918RPD and VigorAP912C.

Support Model and Version

·         For the full model support list, please refer to Compatible Devices section in URL https://www.draytek.com/products/vigoracs-2/

Improvements

·                     -  Make a record when testing the RESTful API.

·                    -  Allows opening several router pages in different tabs using any browser.

·                    -  Add the column, Last inform time, on NETWORK MENU >> Monitoring >> Device.

·                     -  Add a message to notify users to restart ACS after changing System Parameters.

·                     -  Fixed: An issue of floor plan upload.

·                    -  Fixed:  An issue of PoE statistics display.

·                     -  Fixed: An issue of authentication via Radius server.

·                     -  Fixed: An issue of displaying the traffic / client graph.

·                    -  Fixed: An issue of incorrect time stamp on user login log.

·                   -    Fixed: An issue of browsing the router pages in different tabs.

·                     -  Fixed: An issue of displaying connection time on NETWORK MENU>>Statistics.

·                     -  Fixed: An issue of searching device(s) by MAC address on NETWORK MENU >> Monitoring >> Clients.

·                     -  Fixed: An issue of displaying the IP object on DEVICE MENU >> Configuration >> Objects Setting.

Known Issue

·         Database (with MariaDB version 10.3.12) is only available for the user who installs VigorACS 2 for the first time. If your computer has installed MariaDB, do not upgrade the database version to prevent data loss.

Click here for more details.

For existing customers wishing to upgrade to the latest release, please contact us at support@draytek.com.au for download instructions.

 

To subscribe to our regular news updates, click on “Subscribe” on this page or login into your i-helpdesk account and enable the “Subscribe” option.



If you no longer wish to receive e-mails from us, please reply with "Unsubscribe".
For more information on i-Lan Technology Pty visit 
http://www.i-lan.com.au/support/terms-conditions or email support@i-lan.com.au if you have a specific question that you would like addressed.

 



    • Related Articles

    • Weekly Update 26 November 2020

      Latest Application Notes Security What should I do when Vigor Router isgetting the message “ARP Address Mismatch” in Syslog? This application note describes how to adjust router settings when you see the syslog message: “Arp address mismatch – Source ...
    • Weekly Update 14 April 2021

      Latest Application Notes LAN Forward All DNS Queries to a Private DNS Server The latest firmware for DrayTek routers now includes an option to forward all DNS requests to a private DNS server regardless of the setting in the client PC. This ...
    • Weekly Update 3 April 2024

      Security Advisory Information Disclosure Vulnerability (CVE-2024-23721) Release Date: 2024-03-27 A vulnerability related to the disclosure of sensitive information has been discovered, potentially allowing an unauthenticated attacker to retrieve the ...
    • Weekly Update 7 January 2021

      Latest Application Notes WAN PPPoE Overview and Troubleshooting ways When PPPoE authentication issues are encountered it helps to understand the processes involved to troubleshoot and find out what is causing the issue.  This article describes the 6 ...
    • Weekly Update 13 February 2020

      Security Advisory Vigor3900 / Vigor2960 / Vigor300B Router Web Management Page Vulnerability (CVE-2020-8515) A vulnerability has been discovered that allows attackers to gain unauthorised remote access to the router management page.  This has been ...