Unauthenticated RCE in DrayTek Vigor Routers DrayOS HTTP CGI Request Processing
CVE-2025-10547 is a remote code execution vulnerability affecting DrayTek Vigor routers running DrayOS. The flaw is in the HTTP CGI request arguments processing component, including the WebUI/LAN web administration interface and referenced EasyVPN-related exposure, and is caused by use of an uninitialized variable. A remote attacker can send crafted HTTP or HTTPS requests to the router’s web interface, triggering memory corruption. In some cases this can crash the device; in successful exploitation scenarios it can lead to arbitrary code execution on the appliance. The issue is reported as exploitable without authentication or user interaction.
Are you exposed to this one?
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
Impact, mitigation & remediation
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
Impact
What an attacker gets, and what they’ve been doing with it.
Mitigation
If you can’t patch tonight, do this now.
Remediation
Patch, then assume compromise.
Exploits
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Recent activity
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A critical vulnerability in DrayTek, details not specified in the content.
A remote code execution vulnerability in DrayTek Vigor Routers that allows unauthenticated attackers to gain root access.
A high-severity memory corruption vulnerability in DrayTek Vigor Routers running DrayOS, caused by an uninitialized variable in the HTTP CGI request arguments processing, allowing unauthenticated remote code execution (RCE).
An unauthenticated router hijack vulnerability in DrayTek Vigor routers’ web management interface, exploitable via specially crafted HTTP/HTTPS requests without valid credentials.
The version that knows your environment.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.