Complex Mathematics

DrayTek warns Vigor routers may have serious security flaws – here’s what we know




  • DrayTek patches CVE-2025-10547, a firmware flaw enabling crashes or remote code execution
  • Vulnerability affects routers with exposed WebUI or misconfigured ACLs; local access also exploitable
  • Vigor routers are common in SMBs, making them attractive targets for persistent cyberattacks

Network gear manufacturer DrayTek has patched a dangerous vulnerability found in dozens of Vigor business router models, and is urging users to apply the fix as soon as possible.

In a security advisory, DrayTek said it discovered an “uninitialized variables in the firmware” vulnerability in DrayOS (the OS powering Vigor routers) which, if exploited, could result in memory corruption or system crashes. There is also “potential in certain circumstances” to use the bug for remote code execution, as well.





Source link