DrayTek has issued a security advisory regarding a critical vulnerability, tracked as CVE-2025-10547, affecting multiple models of its Vigor routers. The flaw allows remote, unauthenticated attackers to execute arbitrary code by sending specially crafted HTTP or HTTPS requests to the device's Web User Interface (WebUI). Security researcher Pierre-Yves Maes from ChapsVision discovered and reported the vulnerability to DrayTek on July 22, 2025. The vulnerability is caused by an uninitialized stack value, which can be exploited to trigger the free() function on arbitrary memory locations, a technique known as arbitrary free(), ultimately enabling remote code execution (RCE). Successful exploitation may result in memory corruption and system crashes, with the potential for attackers to gain full control of affected devices. DrayTek's advisory emphasizes that while remote WebUI or SSL VPN access can be disabled or restricted using ACLs and VLANs to reduce WAN exposure, the WebUI remains accessible from the LAN side, leaving devices vulnerable to local threats. The affected routers include both older and flagship models widely used in small to medium businesses, prosumer networks, telecom, and direct link service environments. DrayTek has not observed any evidence of active exploitation in the wild as of the time of the advisory. The company strongly urges administrators to apply the recommended firmware updates to mitigate the risk. Specific firmware versions have been released for each impacted model, such as version 4.4.3.6 or later for Vigor1000B, Vigor2962, and Vigor3910/3912, and version 4.5.1 or later for Vigor2135, Vigor2763/2765/2766, and Vigor2865/2866 Series. Other models, including Vigor2915, Vigor2862/2926, Vigor2952/2952P, Vigor3220, Vigor2860/2925, Vigor2133/2762/2832, Vigor2620, and VigorLTE 200n, also have designated firmware updates to address the vulnerability. DrayTek recommends that organizations limit WAN exposure by disabling remote management interfaces or tightly controlling access. The vulnerability highlights the ongoing risks associated with exposing network device management interfaces to the internet. Administrators are advised to review their device configurations and ensure that only trusted users have access to the WebUI, especially from internal networks. The incident underscores the importance of timely patch management and network segmentation to reduce the attack surface. DrayTek's response demonstrates a proactive approach to vulnerability disclosure and mitigation, providing clear guidance and updates to its user base. Organizations using affected DrayTek Vigor routers should prioritize applying the security updates and reviewing their remote access policies to prevent potential exploitation. The case also serves as a reminder for all network device vendors and users to regularly audit and secure management interfaces against emerging threats.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
Subsequent coverage emphasized that successful exploitation of CVE-2025-10547 could give unauthenticated attackers root-level access and full compromise of affected DrayTek Vigor devices. This reinforced the severity of the issue for exposed routers.
CVE-2025-10547 was publicly published as a high-severity issue affecting DrayTek Vigor routers running DrayOS, with a CVSS 3.1 score of 8.8. The advisory described an uninitialized-variable bug in HTTP CGI request argument processing that can enable unauthenticated remote code execution.
DrayTek warned that the vulnerability affects multiple Vigor router lines and advised customers to reduce WAN exposure by disabling remote WebUI or SSL VPN access or restricting access with ACLs and VLANs. The company also urged administrators to apply available firmware updates and said there was no evidence of active exploitation at the time.
ChapsVision researcher Pierre-Yves Maes disclosed a vulnerability later tracked as CVE-2025-10547 affecting multiple DrayTek Vigor routers. The flaw involves crafted HTTP/HTTPS requests to the WebUI that can trigger memory corruption, crashes, and possible remote code execution by unauthenticated attackers.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcecvefeed.io
Open sourcescworld.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.