CVE-2023-33778
Last modified
CVE-2023-33778 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Draytek Vigor Routers firmware versions below 3.9.6/4.2.4, Access Points firmware versions below v1.4.0, Switches firmware versions below 2.6.7, and Myvigor firmware versions below 2.3.2 were discovered to use hardcoded encryption keys which allows attackers to bind any affected device to their own account. Attackers are then able to create WCF and DrayDDNS licenses and synchronize them from the website.. EPSS estimates a 0.60% chance of exploitation in the next 30 days.
Description
Draytek Vigor Routers firmware versions below 3.9.6/4.2.4, Access Points firmware versions below v1.4.0, Switches firmware versions below 2.6.7, and Myvigor firmware versions below 2.3.2 were discovered to use hardcoded encryption keys which allows attackers to bind any affected device to their own account. Attackers are then able to create WCF and DrayDDNS licenses and synchronize them from the website.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Draytek | Myvigor | < 2.3.2 |
| Draytek | Vigorswitch Pq2200xb Firmware | < 2.6.7 |
| Draytek | Vigorswitch Pq2121x Firmware | < 2.6.7 |
| Draytek | Vigorswitch P2540xs Firmware | < 2.6.7 |
| Draytek | Vigorswitch P2280x Firmware | < 2.6.7 |
| Draytek | Vigorswitch P2100 Firmware | < 2.6.7 |
| Draytek | Vigorswitch Q2200x Firmware | < 2.6.7 |
| Draytek | Vigorswitch Q2121x Firmware | < 2.6.7 |
| Draytek | Vigorswitch G2540xs Firmware | < 2.6.7 |
| Draytek | Vigorswitch G2280x Firmware | < 2.6.7 |
| Draytek | Vigorswitch G2121 Firmware | < 2.6.7 |
| Draytek | Vigorswitch G2100 Firmware | < 2.6.7 |
| Draytek | Vigorswitch Fx2120 Firmware | < 2.6.7 |
| Draytek | Vigorswitch P1282 Firmware | < 2.6.7 |
| Draytek | Vigorswitch G1282 Firmware | < 2.6.7 |
| Draytek | Vigorswitch G1085 Firmware | < 2.6.7 |
| Draytek | Vigorswitch G1080 Firmware | < 2.6.7 |
| Draytek | Vigorap 903 Firmware | < 1.4.0 |
| Draytek | Vigorap 912c Firmware | < 1.4.0 |
| Draytek | Vigorap 918r Firmware | < 1.4.0 |
| Draytek | Vigorap 1060c Firmware | < 1.4.0 |
| Draytek | Vigorap 906 Firmware | < 1.4.0 |
| Draytek | Vigorap 960c Firmware | < 1.4.0 |
| Draytek | Vigorap 1000c Firmware | < 1.4.0 |
| Draytek | Vigor2766ac Firmware | < 3.9.6 |
| Draytek | Vigor2766ac Firmware | >= 4.0.0, < 4.2.4 |
| Draytek | Vigor2766ax Firmware | < 3.9.6 |
| Draytek | Vigor2766ax Firmware | >= 4.0.0, < 4.2.4 |
| Draytek | Vigor2766vac Firmware | < 3.9.6 |
| Draytek | Vigor2766vac Firmware | >= 4.0.0, < 4.2.4 |
| Draytek | Vigor2765ax Firmware | < 3.9.6 |
| Draytek | Vigor2765ax Firmware | >= 4.0.0, < 4.2.4 |
| Draytek | Vigor2765vac Firmware | < 3.9.6 |
| Draytek | Vigor2765vac Firmware | >= 4.0.0, < 4.2.4 |
| Draytek | Vigor2765ac Firmware | < 3.9.6 |
| Draytek | Vigor2765ac Firmware | >= 4.0.0, < 4.2.4 |
| Draytek | Vigor2763ac Firmware | < 3.9.6 |
| Draytek | Vigor2763ac Firmware | >= 4.0.0, < 4.2.4 |
| Draytek | Vigor2620l Firmware | < 3.9.6 |
| Draytek | Vigor2620l Firmware | >= 4.0.0, < 4.2.4 |
| Draytek | Vigor2620ln Firmware | < 3.9.6 |
| Draytek | Vigor2620ln Firmware | >= 4.0.0, < 4.2.4 |
| Draytek | Vigorlte 200n Firmware | < 3.9.6 |
| Draytek | Vigorlte 200n Firmware | >= 4.0.0, < 4.2.4 |
| Draytek | Vigor2915ac Firmware | < 3.9.6 |
| Draytek | Vigor2915ac Firmware | >= 4.0.0, < 4.2.4 |
| Draytek | Vigor2135ac Firmware | < 3.9.6 |
| Draytek | Vigor2135ac Firmware | >= 4.0.0, < 4.2.4 |
| Draytek | Vigor2135ax Firmware | < 3.9.6 |
| Draytek | Vigor2135ax Firmware | >= 4.0.0, < 4.2.4 |
Showing 50 of 120 affected configurations. See NVD for the full list.
References
- https://gist.github.com/Ji4n1ng/6d028709d39458f5ab95b3ea211225efExploit, Third Party Advisory
- https://gist.github.com/Ji4n1ng/6d028709d39458f5ab95b3ea211225efExploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-33778?
How severe is CVE-2023-33778?
How do I fix CVE-2023-33778?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-33763eMedia Consulting simpleRedak up to v2.47.23.05 was discover…6.1
- CVE-2023-33764eMedia Consulting simpleRedak up to v2.47.23.05 was discover…5.4
- CVE-2023-33768Incorrect signature verification of the firmware during the …6.5
- CVE-2023-3377Improper Neutralization of Special Elements used in an SQL C…9.8
- CVE-2023-33770Real Estate Management System v1.0 was discovered to contain…5.1
- CVE-2023-33777An issue in /functions/fbaorder.php of Prestashop amazon bef…5.3
- CVE-2023-33779A lateral privilege escalation vulnerability in XXL-Job v2.4…8.8
- CVE-2023-3378Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2023-33780A stored cross-site scripting (XSS) vulnerability in TFDi De…5.4
- CVE-2023-33781An issue in D-Link DIR-842V2 v1.0.3 allows attackers to exec…8.8
- CVE-2023-33782D-Link DIR-842V2 v1.0.3 was discovered to contain a command …8.8
- CVE-2023-33785A stored cross-site scripting (XSS) vulnerability in the Cre…5.4
Are you affected by CVE-2023-33778?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
