- 26 April 2024
- 15 May 2024
- 2 min read
Speak to an expert : Live Chat
The vulnerability (CVE-2022-32548) affects a number of Vigor models that Exa and our customers have deployed in the past few years, specifically the following devices:
On a standard out-of-the-box configuration, or Exa’s default managed configuration, management pages can’t be reached through Wide Area Network (WAN) interfaces. However, this doesn’t protect malicious activity within the Local Area Network (LAN). As such, any Vigor running vulnerable firmware can be exploited within the LAN.
Draytek has released firmware updates to patch the vulnerability, so if you are managing your device internally, we recommend updating your firmware immediately. Before doing the upgrade, take a backup of your current config in case you need it later.
Anyone using SSL VPN should immediately disable this feature to remove access to the web interface from the internet, until a firmware update is applied. Once this update has been applied, customers should be able to switch the SSL VPN on again.
You should also review whether remote access to the device management pages is needed. If it is, this should always (as best practice) be locked down to a limited number of management IP addresses/ranges.
You don’t need to take any action if we are managing your device, you will be contacted directly.
If you would like us to manage the deployment of firmware upgrades for you, whilst also gaining the security of a replacement router should anything happen, you can get in touch with us about our RFL (Router for Life) service.
For more information regarding vulnerability (CVE-2022-32548) visit the Draytek website.
For further information on our IMS Policy contact:
Exa is a trading name of Exa Networks Limited | Registered Company Number: 04922037 | VAT Number: 829 1565 09 | © Copyright Exa Networks Limited 2024 | All Rights Reserved
Exa is a trading name of Exa Networks Limited
Registered Company Number: 04922037
VAT Number: 829 1565 09
© Copyright Exa Networks Limited 2024 | All Rights Reserved
Cookie | Duration | Description |
---|---|---|
cookielawinfo-checkbox-analytics | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics". |
cookielawinfo-checkbox-functional | 11 months | The cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional". |
cookielawinfo-checkbox-necessary | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary". |
cookielawinfo-checkbox-others | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other. |
cookielawinfo-checkbox-performance | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance". |
viewed_cookie_policy | 11 months | The cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data. |
Monday: 8:30am – 5pm
Tuesday: 8:30am – 5pm
Wednesday: 8:30am – 5pm
Thursday: 8:30am – 5pm
Friday: 8:30am – 5pm
Saturday: Closed
Sunday: Closed
Email: helpdesk@exa.net.uk
Phone: 0345 145 1234
Monday: 8am – 6pm
Tuesday: 8am – 6pm
Wednesday: 8am – 6pm
Thursday: 8am – 6pm
Friday: 8am – 6pm
Saturday: 10am – 4pm
Sunday: 10am – 4pm