What's new
  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

Draytek Security Notice

As a user of a Vigor 130 I got the following notice which can affect a lot of Draytek products - https://www.draytek.com/en/about/ne...of-urgent-security-updates-to-draytek-routers


Already posted :

https://www.snbforums.com/threads/security-advisory-csrf-dns-attacks-draytek.46668/

They have rushed out new firmware which apparently only adds a captcha to the log in , bet that won't help much. Also people running 2960's are seeing the same attack but DrayTek deny that model is affected.

The DrayTek log in is a joke, you can't change the username from default "admin".

DrayTek also still use telnet .........
 
If you hit a bad DNS server they can load anything they want on your PC. I would recommend creating an access list to block all other DNS than your local ISP's DNS. This way if your DNS changes then the PCs go off line because they are using a blocked DNS server.
 
Similar threads
Thread starter Title Forum Replies Date
P Philips Hue Bridge triggers performance notice Routers 2

Similar threads

Latest threads

Support SNBForums w/ Amazon

If you'd like to support SNBForums, just use this link and buy anything on Amazon. Thanks!

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!
Back
Top