A study by the Centre for Cyber Security Belgium (CCB) shows that DrayTek Vigor2960 routers are affected by the unidentified vulnerability, whilst other DrayTek devices are likely impacted.
The vulnerability allows attackers to bypass the authentication procedures and remotely inject or execute code on the operating system of the DrayTek Vigor2960 routers.
DrayTek has developed patches for some recently disclosed security vulnerabilities, however, it is not clear whether the aforementioned exploited vulnerability has been patched. Nevertheless, the CCB strongly recommends that users perform the latest security updates on DrayTek routers.
Checking for backdoors
The CCB has performed penetration tests, showing that previously installed backdoors on DrayTek Vigor2960 routers using version 1.4 of the firmware were not removed after patching to version 1.5.1.1. This suggests that a compromised router will remain compromised even after upgrading to version 1.5.1.1.