Executive brief
Multiple DrayTek wireless access points contain a security flaw where a weak, hardcoded password is used for the internal routing service. This allows an attacker on the network to take control of how the device directs traffic. An exploit could lead to network outages, the redirection of user data, or unauthorized interception of sensitive communications.
Technical details
A vulnerability exists in the configuration of the Routing Information Protocol (RIP) daemon (ripd) within certain DrayTek VigorAP firmware versions. The 'password' property in the ripd.conf configuration file is set to a hardcoded weak value (CWE-798). An unauthenticated attacker with network access can use this credential to gain unauthorized control over the routing daemon. This allows for the injection of malicious routes, potentially leading to traffic interception (Man-in-the-Middle) or a Denial of Service (DoS) by disrupting network pathing. Affected models include AP903, AP912C, and AP918R.
Affected products
- DrayTek VigorAP 903 1.4.18
- DrayTek VigorAP 912C 1.4.9
- DrayTek VigorAP 918R 1.4.9
Timeline
- 2025-08-04: disclosed: Initial NVD publication date
- 2025-08-04: advisory: CISA-ADP enrichment added CVSS and CWE data