Skip to content
COOEY

FAIL › dossier

DrayTek

VENDOR

· dossier confidence 20%

DrayTek, a provider of networking equipment, has a history of significant security vulnerabilities including remote code execution and path traversal flaws, some of which have been exploited in the wild. This poses a risk to organizations relying on their products and requires careful assessment and mitigation.

PROFILE
CategoryNetworkingWhat they doDrayTek provides routers, firewalls, switches, and wireless access points for businesses. They offer a range of networking solutions including VPN firewalls, load balancing routers, and network management systems. Websitehttps://www.draytek.co.uk/support/downloads/vigor-2865 ↗
SECURITY POSTURE

DrayTek has a concerning history of high-severity vulnerabilities in their routers and access points, frequently involving remote code execution and path traversal. Their products have been actively exploited in the wild, indicating a potential lack of robust security practices.

Notable failures
  • CVE-2024-12987 (RCE)
  • CVE-2020-15415 (RCE)
  • CVE-2021-20124 (Path Traversal)
  • CVE-2021-20123 (Path Traversal)
  • CVE-2020-8515 (RCE)
Patterns: Repeated RCE vulnerabilities; Unauthenticated path traversal vulnerabilities; Vulnerabilities affecting multiple product lines
Reputationsevere-fallout (-1.00) · 1 trusted sources Coveragecooey
FAILURE HISTORY · 5
DATEEVENTSEVSUMMARY
2024-09-30 CVE-2020-15415 high DrayTek routers allow remote code execution via filename injection in Python script uploads.
2024-09-03 CVE-2021-20123 high DrayTek's VigorConnect router allows unauthenticated attackers to download arbitrary OS files with root privileges via a path traversal flaw in the DownloadFileServlet endpoint.
2021-11-03 CVE-2020-8515 high DrayTek Vigor routers suffered a remote code execution flaw actively exploited in the wild, enabling attackers to take full control of network devices.
2025-05-15 CVE-2024-12987 high DrayTek routers are vulnerable to OS command injection, currently being exploited in the wild, impacting network security and compliance posture.
2024-09-03 CVE-2021-20124 high DrayTek's VigorConnect router allows unauthenticated attackers to download arbitrary OS files with root privileges via a path traversal flaw in the WebServlet endpoint.
SENTIMENT · TRUSTED SOURCES
synthesissevere-fallout-1.00
cooey ↗severe-fallout-1.00
"…"
DOSSIER SOURCES
Open questions: What is DrayTek's current patching cadence? · What security development lifecycle practices are in place? · What is the ownership structure of DrayTek?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-28 12:45:18.737512+00:00