ID

VAR-202306-0072


CVE

CVE-2023-33778


TITLE

Draytek Vigor Routers Trust Management Issue Vulnerability

Trust: 0.6

sources: CNNVD: CNNVD-202306-003

DESCRIPTION

Draytek Vigor Routers firmware versions below 3.9.6/4.2.4, Access Points firmware versions below v1.4.0, Switches firmware versions below 2.6.7, and Myvigor firmware versions below 2.3.2 were discovered to use hardcoded encryption keys which allows attackers to bind any affected device to their own account. Attackers are then able to create WCF and DrayDDNS licenses and synchronize them from the website

Trust: 0.99

sources: NVD: CVE-2023-33778 // VULMON: CVE-2023-33778

AFFECTED PRODUCTS

vendor:draytekmodel:vigor2832nscope:gteversion:4.0.0

Trust: 1.0

vendor:draytekmodel:vigor2962scope:ltversion:4.2.4

Trust: 1.0

vendor:draytekmodel:vigor2763acscope:ltversion:3.9.6

Trust: 1.0

vendor:draytekmodel:vigor167scope:gteversion:4.0.0

Trust: 1.0

vendor:draytekmodel:vigorswitch pq2200xbscope:ltversion:2.6.7

Trust: 1.0

vendor:draytekmodel:vigor2862bscope:ltversion:4.2.4

Trust: 1.0

vendor:draytekmodel:vigor2620lnscope:ltversion:3.9.6

Trust: 1.0

vendor:draytekmodel:vigor2766acscope:ltversion:3.9.6

Trust: 1.0

vendor:draytekmodel:vigor2927vacscope:ltversion:3.9.6

Trust: 1.0

vendor:draytekmodel:vigor2927acscope:ltversion:3.9.6

Trust: 1.0

vendor:draytekmodel:vigor2862vacscope:ltversion:3.9.6

Trust: 1.0

vendor:draytekmodel:vigor2866axscope:gteversion:4.0.0

Trust: 1.0

vendor:draytekmodel:vigor165scope:gteversion:4.0.0

Trust: 1.0

vendor:draytekmodel:vigor3910scope:gteversion:4.0.0

Trust: 1.0

vendor:draytekmodel:vigor2927axscope:ltversion:4.2.4

Trust: 1.0

vendor:draytekmodel:vigorap 1060cscope:ltversion:1.4.0

Trust: 1.0

vendor:draytekmodel:vigor166scope:ltversion:4.2.4

Trust: 1.0

vendor:draytekmodel:vigor2862lnscope:ltversion:4.2.4

Trust: 1.0

vendor:draytekmodel:vigorswitch g1085scope:ltversion:2.6.7

Trust: 1.0

vendor:draytekmodel:vigor2766vacscope:ltversion:3.9.6

Trust: 1.0

vendor:draytekmodel:vigorswitch fx2120scope:ltversion:2.6.7

Trust: 1.0

vendor:draytekmodel:vigorswitch p1282scope:ltversion:2.6.7

Trust: 1.0

vendor:draytekmodel:vigor2862acscope:ltversion:3.9.6

Trust: 1.0

vendor:draytekmodel:vigor2620lscope:ltversion:4.2.4

Trust: 1.0

vendor:draytekmodel:vigorap 960cscope:ltversion:1.4.0

Trust: 1.0

vendor:draytekmodel:vigor2766acscope:gteversion:4.0.0

Trust: 1.0

vendor:draytekmodel:vigorap 903scope:ltversion:1.4.0

Trust: 1.0

vendor:draytekmodel:vigor2832nscope:ltversion:3.9.6

Trust: 1.0

vendor:draytekmodel:vigor167scope:ltversion:3.9.6

Trust: 1.0

vendor:draytekmodel:vigor2865vacscope:ltversion:4.2.4

Trust: 1.0

vendor:draytekmodel:vigorswitch q2200xscope:ltversion:2.6.7

Trust: 1.0

vendor:draytekmodel:vigor2765axscope:ltversion:4.2.4

Trust: 1.0

vendor:draytekmodel:vigor2135acscope:ltversion:4.2.4

Trust: 1.0

vendor:draytekmodel:vigor2862lscope:ltversion:3.9.6

Trust: 1.0

vendor:draytekmodel:vigor130scope:ltversion:4.2.4

Trust: 1.0

vendor:draytekmodel:vigor2766axscope:ltversion:3.9.6

Trust: 1.0

vendor:draytekmodel:vigor2926 plusscope:ltversion:4.2.4

Trust: 1.0

vendor:draytekmodel:vigor2862acscope:gteversion:4.0.0

Trust: 1.0

vendor:draytekmodel:vigor2135vacscope:ltversion:4.2.4

Trust: 1.0

vendor:draytekmodel:vigorap 918rscope:ltversion:1.4.0

Trust: 1.0

vendor:draytekmodel:vigor2866axscope:ltversion:3.9.6

Trust: 1.0

vendor:draytekmodel:vigor2865axscope:ltversion:4.2.4

Trust: 1.0

vendor:draytekmodel:vigor3910scope:ltversion:3.9.6

Trust: 1.0

vendor:draytekmodel:vigor1000bscope:ltversion:4.2.4

Trust: 1.0

vendor:draytekmodel:vigor2135axscope:ltversion:4.2.4

Trust: 1.0

vendor:draytekmodel:vigor2927lscope:ltversion:4.2.4

Trust: 1.0

vendor:draytekmodel:vigor2866lacscope:gteversion:4.0.0

Trust: 1.0

vendor:draytekmodel:vigor2862nscope:ltversion:3.9.6

Trust: 1.0

vendor:draytekmodel:vigorswitch g2540xsscope:ltversion:2.6.7

Trust: 1.0

vendor:draytekmodel:vigor2866acscope:ltversion:4.2.4

Trust: 1.0

vendor:draytekmodel:vigor2765acscope:ltversion:4.2.4

Trust: 1.0

vendor:draytekmodel:vigor2915acscope:gteversion:4.0.0

Trust: 1.0

vendor:draytekmodel:vigor2862lscope:gteversion:4.0.0

Trust: 1.0

vendor:draytekmodel:vigor2766axscope:gteversion:4.0.0

Trust: 1.0

vendor:draytekmodel:vigor2927fscope:ltversion:3.9.6

Trust: 1.0

vendor:draytekmodel:vigor2927lacscope:ltversion:4.2.4

Trust: 1.0

vendor:draytekmodel:vigor2865lacscope:gteversion:4.0.0

Trust: 1.0

vendor:draytekmodel:vigor166scope:gteversion:4.0.0

Trust: 1.0

vendor:draytekmodel:vigorswitch g1282scope:ltversion:2.6.7

Trust: 1.0

vendor:draytekmodel:vigor2862lacscope:gteversion:4.0.0

Trust: 1.0

vendor:draytekmodel:vigor2865lscope:gteversion:4.0.0

Trust: 1.0

vendor:draytekmodel:vigor2962scope:ltversion:3.9.6

Trust: 1.0

vendor:draytekmodel:vigorlte 200nscope:gteversion:4.0.0

Trust: 1.0

vendor:draytekmodel:vigor2862bscope:ltversion:3.9.6

Trust: 1.0

vendor:draytekmodel:vigor2862bnscope:gteversion:4.0.0

Trust: 1.0

vendor:draytekmodel:vigor2862nscope:gteversion:4.0.0

Trust: 1.0

vendor:draytekmodel:vigor2765vacscope:gteversion:4.0.0

Trust: 1.0

vendor:draytekmodel:vigor2763acscope:ltversion:4.2.4

Trust: 1.0

vendor:draytekmodel:vigor2620lnscope:gteversion:4.0.0

Trust: 1.0

vendor:draytekmodel:vigor2866lscope:ltversion:4.2.4

Trust: 1.0

vendor:draytekmodel:vigor2865acscope:gteversion:4.0.0

Trust: 1.0

vendor:draytekmodel:vigor2915acscope:ltversion:3.9.6

Trust: 1.0

vendor:draytekmodel:vigorswitch g2100scope:ltversion:2.6.7

Trust: 1.0

vendor:draytekmodel:vigor2620lnscope:ltversion:4.2.4

Trust: 1.0

vendor:draytekmodel:vigorswitch p2280xscope:ltversion:2.6.7

Trust: 1.0

vendor:draytekmodel:vigor2926 plusscope:gteversion:4.0.0

Trust: 1.0

vendor:draytekmodel:vigor2927vacscope:ltversion:4.2.4

Trust: 1.0

vendor:draytekmodel:vigor2962scope:gteversion:4.0.0

Trust: 1.0

vendor:draytekmodel:vigor2620lscope:ltversion:3.9.6

Trust: 1.0

vendor:draytekmodel:vigor2862bscope:gteversion:4.0.0

Trust: 1.0

vendor:draytekmodel:vigor2927acscope:ltversion:4.2.4

Trust: 1.0

vendor:draytekmodel:myvigorscope:ltversion:2.3.2

Trust: 1.0

vendor:draytekmodel:vigor2862vacscope:ltversion:4.2.4

Trust: 1.0

vendor:draytekmodel:vigor2862lacscope:ltversion:3.9.6

Trust: 1.0

vendor:draytekmodel:vigor2865lscope:ltversion:3.9.6

Trust: 1.0

vendor:draytekmodel:vigor2135fvacscope:ltversion:4.2.4

Trust: 1.0

vendor:draytekmodel:vigorswitch p2540xsscope:ltversion:2.6.7

Trust: 1.0

vendor:draytekmodel:vigor2766vacscope:ltversion:4.2.4

Trust: 1.0

vendor:draytekmodel:vigor2866vacscope:ltversion:4.2.4

Trust: 1.0

vendor:draytekmodel:vigor2862bnscope:ltversion:3.9.6

Trust: 1.0

vendor:draytekmodel:vigor2927axscope:gteversion:4.0.0

Trust: 1.0

vendor:draytekmodel:vigor2765vacscope:ltversion:3.9.6

Trust: 1.0

vendor:draytekmodel:vigorswitch p2100scope:ltversion:2.6.7

Trust: 1.0

vendor:draytekmodel:vigor2866lacscope:ltversion:4.2.4

Trust: 1.0

vendor:draytekmodel:vigor2862lnscope:gteversion:4.0.0

Trust: 1.0

vendor:draytekmodel:vigor2135vacscope:ltversion:3.9.6

Trust: 1.0

vendor:draytekmodel:vigor2832nscope:ltversion:4.2.4

Trust: 1.0

vendor:draytekmodel:vigor167scope:ltversion:4.2.4

Trust: 1.0

vendor:draytekmodel:vigor2865acscope:ltversion:3.9.6

Trust: 1.0

vendor:draytekmodel:vigor1000bscope:ltversion:3.9.6

Trust: 1.0

vendor:draytekmodel:vigorap 1000cscope:ltversion:1.4.0

Trust: 1.0

vendor:draytekmodel:vigor2135axscope:ltversion:3.9.6

Trust: 1.0

vendor:draytekmodel:vigor2927lscope:ltversion:3.9.6

Trust: 1.0

vendor:draytekmodel:vigor2865lacscope:ltversion:4.2.4

Trust: 1.0

vendor:draytekmodel:vigorswitch g2280xscope:ltversion:2.6.7

Trust: 1.0

vendor:draytekmodel:vigorap 912cscope:ltversion:1.4.0

Trust: 1.0

vendor:draytekmodel:vigor165scope:ltversion:4.2.4

Trust: 1.0

vendor:draytekmodel:vigorlte 200nscope:ltversion:4.2.4

Trust: 1.0

vendor:draytekmodel:vigor2765acscope:ltversion:3.9.6

Trust: 1.0

vendor:draytekmodel:vigor2866axscope:ltversion:4.2.4

Trust: 1.0

vendor:draytekmodel:vigor2866acscope:ltversion:3.9.6

Trust: 1.0

vendor:draytekmodel:vigor2765axscope:gteversion:4.0.0

Trust: 1.0

vendor:draytekmodel:vigor2135acscope:gteversion:4.0.0

Trust: 1.0

vendor:draytekmodel:vigor130scope:gteversion:4.0.0

Trust: 1.0

vendor:draytekmodel:vigor3910scope:ltversion:4.2.4

Trust: 1.0

vendor:draytekmodel:vigor2135vacscope:gteversion:4.0.0

Trust: 1.0

vendor:draytekmodel:vigorswitch g2121scope:ltversion:2.6.7

Trust: 1.0

vendor:draytekmodel:vigor2865axscope:gteversion:4.0.0

Trust: 1.0

vendor:draytekmodel:vigor2927axscope:ltversion:3.9.6

Trust: 1.0

vendor:draytekmodel:vigorswitch pq2121xscope:ltversion:2.6.7

Trust: 1.0

vendor:draytekmodel:vigor2135axscope:gteversion:4.0.0

Trust: 1.0

vendor:draytekmodel:vigor2927lscope:gteversion:4.0.0

Trust: 1.0

vendor:draytekmodel:vigor166scope:ltversion:3.9.6

Trust: 1.0

vendor:draytekmodel:vigor2766acscope:ltversion:4.2.4

Trust: 1.0

vendor:draytekmodel:vigor2862lnscope:ltversion:3.9.6

Trust: 1.0

vendor:draytekmodel:vigor2927fscope:gteversion:4.0.0

Trust: 1.0

vendor:draytekmodel:vigor2866acscope:gteversion:4.0.0

Trust: 1.0

vendor:draytekmodel:vigor2765acscope:gteversion:4.0.0

Trust: 1.0

vendor:draytekmodel:vigor2866lscope:ltversion:3.9.6

Trust: 1.0

vendor:draytekmodel:vigor2927lacscope:gteversion:4.0.0

Trust: 1.0

vendor:draytekmodel:vigor2865vacscope:ltversion:3.9.6

Trust: 1.0

vendor:draytekmodel:vigor2862acscope:ltversion:4.2.4

Trust: 1.0

vendor:draytekmodel:vigor2765axscope:ltversion:3.9.6

Trust: 1.0

vendor:draytekmodel:vigor2135acscope:ltversion:3.9.6

Trust: 1.0

vendor:draytekmodel:vigor130scope:ltversion:3.9.6

Trust: 1.0

vendor:draytekmodel:vigor2926 plusscope:ltversion:3.9.6

Trust: 1.0

vendor:draytekmodel:vigorap 906scope:ltversion:1.4.0

Trust: 1.0

vendor:draytekmodel:vigor2915acscope:ltversion:4.2.4

Trust: 1.0

vendor:draytekmodel:vigor2135fvacscope:ltversion:3.9.6

Trust: 1.0

vendor:draytekmodel:vigor2865axscope:ltversion:3.9.6

Trust: 1.0

vendor:draytekmodel:vigor2620lscope:gteversion:4.0.0

Trust: 1.0

vendor:draytekmodel:vigor2866vacscope:ltversion:3.9.6

Trust: 1.0

vendor:draytekmodel:vigor2763acscope:gteversion:4.0.0

Trust: 1.0

vendor:draytekmodel:vigor2866lscope:gteversion:4.0.0

Trust: 1.0

vendor:draytekmodel:vigor2862lscope:ltversion:4.2.4

Trust: 1.0

vendor:draytekmodel:vigor2766axscope:ltversion:4.2.4

Trust: 1.0

vendor:draytekmodel:vigor2866lacscope:ltversion:3.9.6

Trust: 1.0

vendor:draytekmodel:vigor2927vacscope:gteversion:4.0.0

Trust: 1.0

vendor:draytekmodel:vigor2862lacscope:ltversion:4.2.4

Trust: 1.0

vendor:draytekmodel:vigor2865lscope:ltversion:4.2.4

Trust: 1.0

vendor:draytekmodel:vigor2927fscope:ltversion:4.2.4

Trust: 1.0

vendor:draytekmodel:vigor2865vacscope:gteversion:4.0.0

Trust: 1.0

vendor:draytekmodel:vigor2927acscope:gteversion:4.0.0

Trust: 1.0

vendor:draytekmodel:vigor2862vacscope:gteversion:4.0.0

Trust: 1.0

vendor:draytekmodel:vigor2927lacscope:ltversion:3.9.6

Trust: 1.0

vendor:draytekmodel:vigorswitch g1080scope:ltversion:2.6.7

Trust: 1.0

vendor:draytekmodel:vigor2862bnscope:ltversion:4.2.4

Trust: 1.0

vendor:draytekmodel:vigor2865lacscope:ltversion:3.9.6

Trust: 1.0

vendor:draytekmodel:vigor2862nscope:ltversion:4.2.4

Trust: 1.0

vendor:draytekmodel:vigor2135fvacscope:gteversion:4.0.0

Trust: 1.0

vendor:draytekmodel:vigor2765vacscope:ltversion:4.2.4

Trust: 1.0

vendor:draytekmodel:vigor2766vacscope:gteversion:4.0.0

Trust: 1.0

vendor:draytekmodel:vigor2866vacscope:gteversion:4.0.0

Trust: 1.0

vendor:draytekmodel:vigor165scope:ltversion:3.9.6

Trust: 1.0

vendor:draytekmodel:vigorlte 200nscope:ltversion:3.9.6

Trust: 1.0

vendor:draytekmodel:vigorswitch q2121xscope:ltversion:2.6.7

Trust: 1.0

vendor:draytekmodel:vigor1000bscope:gteversion:4.0.0

Trust: 1.0

vendor:draytekmodel:vigor2865acscope:ltversion:4.2.4

Trust: 1.0

sources: NVD: CVE-2023-33778

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2023-33778
value: CRITICAL

Trust: 1.0

134c704f-9b21-4f2e-91b3-4a467353bcc0: CVE-2023-33778
value: CRITICAL

Trust: 1.0

CNNVD: CNNVD-202306-003
value: CRITICAL

Trust: 0.6

nvd@nist.gov: CVE-2023-33778
baseSeverity: CRITICAL
baseScore: 9.8
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 5.9
version: 3.1

Trust: 2.0

sources: CNNVD: CNNVD-202306-003 // NVD: CVE-2023-33778 // NVD: CVE-2023-33778

PROBLEMTYPE DATA

problemtype:CWE-798

Trust: 1.0

sources: NVD: CVE-2023-33778

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-202306-003

TYPE

trust management problem

Trust: 0.6

sources: CNNVD: CNNVD-202306-003

EXTERNAL IDS

db:NVDid:CVE-2023-33778

Trust: 1.7

db:CNNVDid:CNNVD-202306-003

Trust: 0.6

db:VULMONid:CVE-2023-33778

Trust: 0.1

sources: VULMON: CVE-2023-33778 // CNNVD: CNNVD-202306-003 // NVD: CVE-2023-33778

REFERENCES

url:https://gist.github.com/ji4n1ng/6d028709d39458f5ab95b3ea211225ef

Trust: 1.7

url:https://cxsecurity.com/cveshow/cve-2023-33778/

Trust: 0.6

url:https://nvd.nist.gov

Trust: 0.1

sources: VULMON: CVE-2023-33778 // CNNVD: CNNVD-202306-003 // NVD: CVE-2023-33778

SOURCES

db:VULMONid:CVE-2023-33778
db:CNNVDid:CNNVD-202306-003
db:NVDid:CVE-2023-33778

LAST UPDATE DATE

2025-01-10T23:14:18.414000+00:00


SOURCES UPDATE DATE

db:VULMONid:CVE-2023-33778date:2023-06-01T00:00:00
db:CNNVDid:CNNVD-202306-003date:2023-06-12T00:00:00
db:NVDid:CVE-2023-33778date:2025-01-09T18:15:26.790

SOURCES RELEASE DATE

db:VULMONid:CVE-2023-33778date:2023-06-01T00:00:00
db:CNNVDid:CNNVD-202306-003date:2023-06-01T00:00:00
db:NVDid:CVE-2023-33778date:2023-06-01T04:15:10.313