RULE(RULE ID:338117)

Rule General Information
Release Date: 2024-06-11
Rule Name: Draytek Router addrouting Command Execution Vulnerability
Severity:
CVE ID:
Rule Protection Details
Description: DrayTek is a network equipment manufacturer based in Taiwan, China. Its products include VPN routers, managed switches, wireless aps, and management systems, which are widely used by small and medium-sized enterprises. The DrayTek router addRouting interface has a command execution vulnerability. The vulnerability is due to the system does not filter the user input parameters effectively. An attacker can use this vulnerability to execute arbitrary code on the server side and gain server privileges.
Impact: An attacker can execute arbitrary command via a successful exploit in the context of the vulnerable software.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please contact the software vendor to update the software patch.