Unknown
CVE-2023-33778
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below:
Add References:
CVE-2023-33778
MITRE ATT&CK
Collection
Command and Control
Credential Access
Defense Evasion
Discovery
Execution
Exfiltration
Impact
Initial Access
Lateral Movement
Persistence
Privilege Escalation
Topic Tags
Description
Draytek Vigor Routers firmware versions below 3.9.6/4.2.4, Access Points firmware versions below v1.4.0, Switches firmware versions below 2.6.7, and Myvigor firmware versions below 2.3.2 were discovered to use hardcoded encryption keys which allows attackers to bind any affected device to their own account. Attackers are then able to create WCF and DrayDDNS licenses and synchronize them from the website.
Add Assessment
No one has assessed this topic. Be the first to add your voice to the community.
CVSS V3 Severity and Metrics
General Information
Vendors
Products
- myvigor,
- vigor1000b firmware,
- vigor130 firmware,
- vigor165 firmware,
- vigor166 firmware,
- vigor167 firmware,
- vigor2135ac firmware,
- vigor2135ax firmware,
- vigor2135fvac firmware,
- vigor2135vac firmware,
- vigor2620l firmware,
- vigor2620ln firmware,
- vigor2763ac firmware,
- vigor2765ac firmware,
- vigor2765ax firmware,
- vigor2765vac firmware,
- vigor2766ac firmware,
- vigor2766ax firmware,
- vigor2766vac firmware,
- vigor2832n firmware,
- vigor2862ac firmware,
- vigor2862b firmware,
- vigor2862bn firmware,
- vigor2862l firmware,
- vigor2862lac firmware,
- vigor2862ln firmware,
- vigor2862n firmware,
- vigor2862vac firmware,
- vigor2865ac firmware,
- vigor2865ax firmware,
- vigor2865l firmware,
- vigor2865lac firmware,
- vigor2865vac firmware,
- vigor2866ac firmware,
- vigor2866ax firmware,
- vigor2866l firmware,
- vigor2866lac firmware,
- vigor2866vac firmware,
- vigor2915ac firmware,
- vigor2926 plus firmware,
- vigor2927ac firmware,
- vigor2927ax firmware,
- vigor2927f firmware,
- vigor2927l firmware,
- vigor2927lac firmware,
- vigor2927vac firmware,
- vigor2962 firmware,
- vigor3910 firmware,
- vigorap 1000c firmware,
- vigorap 1060c firmware,
- vigorap 903 firmware,
- vigorap 906 firmware,
- vigorap 912c firmware,
- vigorap 918r firmware,
- vigorap 960c firmware,
- vigorlte 200n firmware,
- vigorswitch fx2120 firmware,
- vigorswitch g1080 firmware,
- vigorswitch g1085 firmware,
- vigorswitch g1282 firmware,
- vigorswitch g2100 firmware,
- vigorswitch g2121 firmware,
- vigorswitch g2280x firmware,
- vigorswitch g2540xs firmware,
- vigorswitch p1282 firmware,
- vigorswitch p2100 firmware,
- vigorswitch p2280x firmware,
- vigorswitch p2540xs firmware,
- vigorswitch pq2121x firmware,
- vigorswitch pq2200xb firmware,
- vigorswitch q2121x firmware,
- vigorswitch q2200x firmware
References
Additional Info
Technical Analysis
Report as Emergent Threat Response
Report as Zero-day Exploit
Report as Exploited in the Wild
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below: