Weekly Update 23 October 2024

Weekly Update 23 October 2024

Security Alert

MultipleVulnerabilities in DrayTek Products (CVE-2024-41583 ~ CVE-2024-41596)

As mentioned in our last newsletter, DrayTek has identified multiple vulnerabilities in DrayTek routers, which have been addressed by issuing updated firmware. These vulnerabilities are CVE-2024-41583 through to CVE-2024-41596. 

Vulnerability Details:

  • Published Date: 2024/10/4
  • CVE IDs: CVE-2024-41583 to CVE-2024-41596
  • Types: Cross-Site Scripting, Denial of Service, Remote Code Execution

CVE number

CVSS

CVE-2024-41583

4.7

CVE-2024-41584

4.7

CVE-2024-41585

6.8

CVE-2024-41586

8

CVE-2024-41587

5.4

CVE-2024-41588

8

CVE-2024-41589

8.8

CVE-2024-41590

8

CVE-2024-41591

6.1

CVE-2024-41592

8

CVE-2024-41593

9.8

CVE-2024-41594

7.5

CVE-2024-41595

8

CVE-2024-41596

8


Action Required:
1. Upgrade your router firmware to the version listed below.
2. Before upgrading:

  • Back up your current configuration (System Maintenance > Config Backup).
  • Use the ".ALL" file to upgrade and preserve your settings.
  • If upgrading from an older version, review the release notes for specific instructions.


3. If remote access is enabled:

  • Disable it unless necessary.
  • Use an access control list (ACL) and enable 2FA if possible.
  • For unpatched routers, disable both remote access (admin) and SSL VPN.
  • Note: ACL does not apply to SSL VPN (Port 443), so temporarily disable SSL VPN until upgraded.

Firmware Versions with Security Fixes

Updated firmware can be downloaded from https://www.draytek.com.au/support/downloads/

 

  • Vigor2133 - 3.9.9
  • Vigor2135 - 4.4.5.3
  • Vigor2620 LTE - 3.9.8.9
  • Vigor2762 - 3.9.9
  • Vigor2765 - 4.4.5.3
  • Vigor2766 - 4.4.5.3
  • Vigor2832 - 3.9.9
  • Vigor2860 / 2860 LTE - 3.9.8
  • Vigor2862 / 2862 LTE - 3.9.9.5
  • Vigor2865 / 2865 LTE - 4.4.5.2
  • Vigor2866 / 2866 LTE - 4.4.5.2
  • Vigor2915 - 4.4.3.2
  • Vigor2925 / 2925 LTE - 3.9.8
  • Vigor2926 / 2926 LTE - 3.9.9.5
  • Vigor2927 / 2927 LTE / 2927L-5G - 4.4.5.5
  • Vigor2952 / 2952 LTE - 3.9.8.2
  • Vigor2962 - 4.3.2.8 4.4.3.1
  • Vigor3220n - 3.9.8.2
  • Vigor3910 - 4.3.2.8 4.4.3.1
  • Vigor3912 - 4.3.6.1

Additional Security Measures:

  • Regularly check for and apply firmware updates.
  • Implement strong, unique passwords for all accounts.
  • Enable and configure firewall settings appropriately.
  • Monitor your network for any suspicious activities.

 

 

Perth DrayTek Training Workshop


i-LAN Technology will hold a one-day DrayTek training workshop in Perth on December 3rd, 2024, at the Metro Hotel in South Perth.

This is an excellent opportunity for DrayTek resellers and network administrators to learn about the latest products and configuration options.

It will also allow you to meet our sales and technical staff, ask questions, and suggest improvements to DrayTek products.

All equipment and training materials will be provided. Light refreshments and lunch will also be provided.

The course includes theory, instruction, and practical hands-on sessions to give you first-hand experience to test each scenario discussed.

The topics to be covered include:

1.       WAN Connectivity Options for the latest DrayTek Routers

2.       Multi-WAN Functions: Load Balance and Failover

3.       High Availability

4.       VLAN and its Applications 


Click here to find out more or register your interest.



Calendar Events from DrayTek HQ

DrayTek HQ often sends notifications of system updates or outages, security notifications, and firmware releases.

Click here for the latest news from DrayTek HQ

 

To subscribe to our regular news updates, click “Subscribe” on this page or log into your i-helpdesk account and enable the “Subscribe” option.




    • Related Articles

    • Weekly Update 4 October 2023

      Upcoming Webinar Free Webinar – Latest Updates to DrayTek Web Content Filter Tuesday 10th October 2023, 12:00 noon AEST Duration: 30 minutes Tune into our next YouTube Premiere webinar: Latest Updates to DrayTek Web Content Filter This webinar looks ...
    • Weekly Update 3 October 2019

      Upcoming Webinar High Availability in DrayTek Routers Tuesday 15th October 2019, 10:00am Duration: 30 minutes  You are invited to attend our next webinar: High Availability in DrayTek Routers This webinar gives an overview of the High Availability ...
    • Weekly Update 1 October 2020

      Upcoming Webinar Free Webinar – Firewall in DrayTek Routers (Part 1) Tuesday 6st October 2020, 10:00am Duration: 30 minutes   Tune in to the first part of our 2-part series of YouTube Premiere webinars: Firewall in DrayTek Routers (Part 1) In this ...
    • Weekly Update 18 October 2022

      Upcoming Webinar Free Webinar – DrayTek VigorACS 3 - Maintenance Tasks Tuesday 25th October 2022, 12:00 noon AEDT Duration: 30 minutes   Tune into our next YouTube Premiere webinar: DrayTek VigorACS 3 - Maintenance Tasks This is the seventh part of ...
    • Weekly Update 10 October 2019

      Upcoming Webinar High Availability in DrayTek Routers Tuesday 15th October 2019, 10:00am Duration: 30 minutes You are invited to attend our next webinar: High Availability in DrayTek Routers This webinar gives an overview of the High Availability ...