FAIL › dossier
DrayTek
VENDOR· dossier confidence 20%
DrayTek, a provider of networking equipment, has a history of significant security vulnerabilities including remote code execution and path traversal flaws, some of which have been exploited in the wild. This poses a risk to organizations relying on their products and requires careful assessment and mitigation.
PROFILE
CategoryNetworkingWhat they doDrayTek provides routers, firewalls, switches, and wireless access points for businesses. They offer a range of networking solutions including VPN firewalls, load balancing routers, and network management systems.
Websitehttps://www.draytek.co.uk/support/downloads/vigor-2865 ↗
SECURITY POSTURE
DrayTek has a concerning history of high-severity vulnerabilities in their routers and access points, frequently involving remote code execution and path traversal. Their products have been actively exploited in the wild, indicating a potential lack of robust security practices.
Notable failures
- CVE-2024-12987 (RCE)
- CVE-2020-15415 (RCE)
- CVE-2021-20124 (Path Traversal)
- CVE-2021-20123 (Path Traversal)
- CVE-2020-8515 (RCE)
Patterns: Repeated RCE vulnerabilities; Unauthenticated path traversal vulnerabilities; Vulnerabilities affecting multiple product lines
FAILURE HISTORY · 5
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2024-09-30 | CVE-2020-15415 | high | DrayTek routers allow remote code execution via filename injection in Python script uploads. |
| 2024-09-03 | CVE-2021-20123 | high | DrayTek's VigorConnect router allows unauthenticated attackers to download arbitrary OS files with root privileges via a path traversal flaw in the DownloadFileServlet endpoint. |
| 2021-11-03 | CVE-2020-8515 | high | DrayTek Vigor routers suffered a remote code execution flaw actively exploited in the wild, enabling attackers to take full control of network devices. |
| 2025-05-15 | CVE-2024-12987 | high | DrayTek routers are vulnerable to OS command injection, currently being exploited in the wild, impacting network security and compliance posture. |
| 2024-09-03 | CVE-2021-20124 | high | DrayTek's VigorConnect router allows unauthenticated attackers to download arbitrary OS files with root privileges via a path traversal flaw in the WebServlet endpoint. |
SENTIMENT · TRUSTED SOURCES
synthesissevere-fallout-1.00
…
DOSSIER SOURCES
- Vigor 2865 - DrayTek · www.draytek.co.uk
- VigorAP 905 - draytek.co.uk · www.draytek.co.uk
- Deadlock Patches and Updates · SteamDB · steamdb.info
Open questions: What is DrayTek's current patching cadence? · What security development lifecycle practices are in place? · What is the ownership structure of DrayTek?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-28 12:45:18.737512+00:00