9.8

CVE-2023-33778

Exploit
Draytek Vigor Routers firmware versions below 3.9.6/4.2.4, Access Points firmware versions below v1.4.0, Switches firmware versions below 2.6.7, and Myvigor firmware versions below 2.3.2 were discovered to use hardcoded encryption keys which allows attackers to bind any affected device to their own account. Attackers are then able to create WCF and DrayDDNS licenses and synchronize them from the website.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
DraytekMyvigor Version < 2.3.2
DraytekVigorswitch Pq2200xb Firmware Version < 2.6.7
   DraytekVigorswitch Pq2200xb Version-
DraytekVigorswitch Pq2121x Firmware Version < 2.6.7
   DraytekVigorswitch Pq2121x Version-
DraytekVigorswitch P2540xs Firmware Version < 2.6.7
   DraytekVigorswitch P2540xs Version-
DraytekVigorswitch P2280x Firmware Version < 2.6.7
   DraytekVigorswitch P2280x Version-
DraytekVigorswitch P2100 Firmware Version < 2.6.7
   DraytekVigorswitch P2100 Version-
DraytekVigorswitch Q2200x Firmware Version < 2.6.7
   DraytekVigorswitch Q2200x Version-
DraytekVigorswitch Q2121x Firmware Version < 2.6.7
   DraytekVigorswitch Q2121x Version-
DraytekVigorswitch G2540xs Firmware Version < 2.6.7
   DraytekVigorswitch G2540xs Version-
DraytekVigorswitch G2280x Firmware Version < 2.6.7
   DraytekVigorswitch G2280x Version-
DraytekVigorswitch G2121 Firmware Version < 2.6.7
   DraytekVigorswitch G2121 Version-
DraytekVigorswitch G2100 Firmware Version < 2.6.7
   DraytekVigorswitch G2100 Version-
DraytekVigorswitch Fx2120 Firmware Version < 2.6.7
   DraytekVigorswitch Fx2120 Version-
DraytekVigorswitch P1282 Firmware Version < 2.6.7
   DraytekVigorswitch P1282 Version-
DraytekVigorswitch G1282 Firmware Version < 2.6.7
   DraytekVigorswitch G1282 Version-
DraytekVigorswitch G1085 Firmware Version < 2.6.7
   DraytekVigorswitch G1085 Version-
DraytekVigorswitch G1080 Firmware Version < 2.6.7
   DraytekVigorswitch G1080 Version-
DraytekVigorap 903 Firmware Version < 1.4.0
   DraytekVigorap 903 Version-
DraytekVigorap 912c Firmware Version < 1.4.0
   DraytekVigorap 912c Version-
DraytekVigorap 918r Firmware Version < 1.4.0
   DraytekVigorap 918r Version-
DraytekVigorap 1060c Firmware Version < 1.4.0
   DraytekVigorap 1060c Version-
DraytekVigorap 906 Firmware Version < 1.4.0
   DraytekVigorap 906 Version-
DraytekVigorap 960c Firmware Version < 1.4.0
   DraytekVigorap 960c Version-
DraytekVigorap 1000c Firmware Version < 1.4.0
   DraytekVigorap 1000c Version-
DraytekVigor2766ac Firmware Version < 3.9.6
   DraytekVigor2766ac Version-
DraytekVigor2766ac Firmware Version >= 4.0.0 < 4.2.4
   DraytekVigor2766ac Version-
DraytekVigor2766ax Firmware Version < 3.9.6
   DraytekVigor2766ax Version-
DraytekVigor2766ax Firmware Version >= 4.0.0 < 4.2.4
   DraytekVigor2766ax Version-
DraytekVigor2766vac Firmware Version < 3.9.6
   DraytekVigor2766vac Version-
DraytekVigor2766vac Firmware Version >= 4.0.0 < 4.2.4
   DraytekVigor2766vac Version-
DraytekVigor2765ax Firmware Version < 3.9.6
   DraytekVigor2765ax Version-
DraytekVigor2765ax Firmware Version >= 4.0.0 < 4.2.4
   DraytekVigor2765ax Version-
DraytekVigor2765vac Firmware Version < 3.9.6
   DraytekVigor2765vac Version-
DraytekVigor2765vac Firmware Version >= 4.0.0 < 4.2.4
   DraytekVigor2765vac Version-
DraytekVigor2765ac Firmware Version < 3.9.6
   DraytekVigor2765ac Version-
DraytekVigor2765ac Firmware Version >= 4.0.0 < 4.2.4
   DraytekVigor2765ac Version-
DraytekVigor2763ac Firmware Version < 3.9.6
   DraytekVigor2763ac Version-
DraytekVigor2763ac Firmware Version >= 4.0.0 < 4.2.4
   DraytekVigor2763ac Version-
DraytekVigor2620l Firmware Version < 3.9.6
   DraytekVigor2620l Version-
DraytekVigor2620l Firmware Version >= 4.0.0 < 4.2.4
   DraytekVigor2620l Version-
DraytekVigor2620ln Firmware Version < 3.9.6
   DraytekVigor2620ln Version-
DraytekVigor2620ln Firmware Version >= 4.0.0 < 4.2.4
   DraytekVigor2620ln Version-
DraytekVigorlte 200n Firmware Version < 3.9.6
   DraytekVigorlte 200n Version-
DraytekVigorlte 200n Firmware Version >= 4.0.0 < 4.2.4
   DraytekVigorlte 200n Version-
DraytekVigor2915ac Firmware Version < 3.9.6
   DraytekVigor2915ac Version-
DraytekVigor2915ac Firmware Version >= 4.0.0 < 4.2.4
   DraytekVigor2915ac Version-
DraytekVigor2135ac Firmware Version < 3.9.6
   DraytekVigor2135ac Version-
DraytekVigor2135ac Firmware Version >= 4.0.0 < 4.2.4
   DraytekVigor2135ac Version-
DraytekVigor2135ax Firmware Version < 3.9.6
   DraytekVigor2135ax Version-
DraytekVigor2135ax Firmware Version >= 4.0.0 < 4.2.4
   DraytekVigor2135ax Version-
DraytekVigor2135fvac Firmware Version < 3.9.6
   DraytekVigor2135fvac Version-
DraytekVigor2135fvac Firmware Version >= 4.0.0 < 4.2.4
   DraytekVigor2135fvac Version-
DraytekVigor2135vac Firmware Version < 3.9.6
   DraytekVigor2135vac Version-
DraytekVigor2135vac Firmware Version >= 4.0.0 < 4.2.4
   DraytekVigor2135vac Version-
DraytekVigor2866ax Firmware Version < 3.9.6
   DraytekVigor2866ax Version-
DraytekVigor2866ax Firmware Version >= 4.0.0 < 4.2.4
   DraytekVigor2866ax Version-
DraytekVigor2866ac Firmware Version < 3.9.6
   DraytekVigor2866ac Version-
DraytekVigor2866ac Firmware Version >= 4.0.0 < 4.2.4
   DraytekVigor2866ac Version-
DraytekVigor2866vac Firmware Version < 3.9.6
   DraytekVigor2866vac Version-
DraytekVigor2866vac Firmware Version >= 4.0.0 < 4.2.4
   DraytekVigor2866vac Version-
DraytekVigor2866l Firmware Version < 3.9.6
   DraytekVigor2866l Version-
DraytekVigor2866l Firmware Version >= 4.0.0 < 4.2.4
   DraytekVigor2866l Version-
DraytekVigor2866lac Firmware Version < 3.9.6
   DraytekVigor2866lac Version-
DraytekVigor2866lac Firmware Version >= 4.0.0 < 4.2.4
   DraytekVigor2866lac Version-
DraytekVigor2865ac Firmware Version < 3.9.6
   DraytekVigor2865ac Version-
DraytekVigor2865ac Firmware Version >= 4.0.0 < 4.2.4
   DraytekVigor2865ac Version-
DraytekVigor2865ax Firmware Version < 3.9.6
   DraytekVigor2865ax Version-
DraytekVigor2865ax Firmware Version >= 4.0.0 < 4.2.4
   DraytekVigor2865ax Version-
DraytekVigor2865vac Firmware Version < 3.9.6
   DraytekVigor2865vac Version-
DraytekVigor2865vac Firmware Version >= 4.0.0 < 4.2.4
   DraytekVigor2865vac Version-
DraytekVigor2865l Firmware Version < 3.9.6
   DraytekVigor2865l Version-
DraytekVigor2865l Firmware Version >= 4.0.0 < 4.2.4
   DraytekVigor2865l Version-
DraytekVigor2865lac Firmware Version < 3.9.6
   DraytekVigor2865lac Version-
DraytekVigor2865lac Firmware Version >= 4.0.0 < 4.2.4
   DraytekVigor2865lac Version-
DraytekVigor2862n Firmware Version < 3.9.6
   DraytekVigor2862n Version-
DraytekVigor2862n Firmware Version >= 4.0.0 < 4.2.4
   DraytekVigor2862n Version-
DraytekVigor2862ac Firmware Version < 3.9.6
   DraytekVigor2862ac Version-
DraytekVigor2862ac Firmware Version >= 4.0.0 < 4.2.4
   DraytekVigor2862ac Version-
DraytekVigor2862vac Firmware Version < 3.9.6
   DraytekVigor2862vac Version-
DraytekVigor2862vac Firmware Version >= 4.0.0 < 4.2.4
   DraytekVigor2862vac Version-
DraytekVigor2862b Firmware Version < 3.9.6
   DraytekVigor2862b Version-
DraytekVigor2862b Firmware Version >= 4.0.0 < 4.2.4
   DraytekVigor2862b Version-
DraytekVigor2862bn Firmware Version < 3.9.6
   DraytekVigor2862bn Version-
DraytekVigor2862bn Firmware Version >= 4.0.0 < 4.2.4
   DraytekVigor2862bn Version-
DraytekVigor2862l Firmware Version < 3.9.6
   DraytekVigor2862l Version-
DraytekVigor2862l Firmware Version >= 4.0.0 < 4.2.4
   DraytekVigor2862l Version-
DraytekVigor2862lac Firmware Version < 3.9.6
   DraytekVigor2862lac Version-
DraytekVigor2862lac Firmware Version >= 4.0.0 < 4.2.4
   DraytekVigor2862lac Version-
DraytekVigor2862ln Firmware Version < 3.9.6
   DraytekVigor2862ln Version-
DraytekVigor2862ln Firmware Version >= 4.0.0 < 4.2.4
   DraytekVigor2862ln Version-
DraytekVigor2832n Firmware Version < 3.9.6
   DraytekVigor2832n Version-
DraytekVigor2832n Firmware Version >= 4.0.0 < 4.2.4
   DraytekVigor2832n Version-
DraytekVigor2927ax Firmware Version < 3.9.6
   DraytekVigor2927ax Version-
DraytekVigor2927ax Firmware Version >= 4.0.0 < 4.2.4
   DraytekVigor2927ax Version-
DraytekVigor2927ac Firmware Version < 3.9.6
   DraytekVigor2927ac Version-
DraytekVigor2927ac Firmware Version >= 4.0.0 < 4.2.4
   DraytekVigor2927ac Version-
DraytekVigor2927vac Firmware Version < 3.9.6
   DraytekVigor2927vac Version-
DraytekVigor2927vac Firmware Version >= 4.0.0 < 4.2.4
   DraytekVigor2927vac Version-
DraytekVigor2927f Firmware Version < 3.9.6
   DraytekVigor2927f Version-
DraytekVigor2927f Firmware Version >= 4.0.0 < 4.2.4
   DraytekVigor2927f Version-
DraytekVigor2927l Firmware Version < 3.9.6
   DraytekVigor2927l Version-
DraytekVigor2927l Firmware Version >= 4.0.0 < 4.2.4
   DraytekVigor2927l Version-
DraytekVigor2927lac Firmware Version < 3.9.6
   DraytekVigor2927lac Version-
DraytekVigor2927lac Firmware Version >= 4.0.0 < 4.2.4
   DraytekVigor2927lac Version-
DraytekVigor2926 Plus Firmware Version < 3.9.6
   DraytekVigor2926 Plus Version-
DraytekVigor2926 Plus Firmware Version >= 4.0.0 < 4.2.4
   DraytekVigor2926 Plus Version-
DraytekVigor2962 Firmware Version < 3.9.6
   DraytekVigor2962 Version-
DraytekVigor2962 Firmware Version >= 4.0.0 < 4.2.4
   DraytekVigor2962 Version-
DraytekVigor1000b Firmware Version < 3.9.6
   DraytekVigor1000b Version-
DraytekVigor1000b Firmware Version >= 4.0.0 < 4.2.4
   DraytekVigor1000b Version-
DraytekVigor3910 Firmware Version < 3.9.6
   DraytekVigor3910 Version-
DraytekVigor3910 Firmware Version >= 4.0.0 < 4.2.4
   DraytekVigor3910 Version-
DraytekVigor165 Firmware Version < 3.9.6
   DraytekVigor165 Version-
DraytekVigor165 Firmware Version >= 4.0.0 < 4.2.4
   DraytekVigor165 Version-
DraytekVigor166 Firmware Version < 3.9.6
   DraytekVigor166 Version-
DraytekVigor166 Firmware Version >= 4.0.0 < 4.2.4
   DraytekVigor166 Version-
DraytekVigor130 Firmware Version < 3.9.6
   DraytekVigor130 Version-
DraytekVigor130 Firmware Version >= 4.0.0 < 4.2.4
   DraytekVigor130 Version-
DraytekVigor167 Firmware Version < 3.9.6
   DraytekVigor167 Version-
DraytekVigor167 Firmware Version >= 4.0.0 < 4.2.4
   DraytekVigor167 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.25% 0.481
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
134c704f-9b21-4f2e-91b3-4a467353bcc0 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-798 Use of Hard-coded Credentials

The product contains hard-coded credentials, such as a password or cryptographic key.