CVE-2025-10547
A remote code execution (RCE) vulnerability was discovered through the EasyVPN and LAN web administration interface of Vigor routers by Drayteck. A script in the LAN web administration interface uses an unitialized variable, allowing an attacker to inject arbitrary commands through memory corruption with specially crafted HTTP requests. Vigor routers are business-grade routers, designed for small to medium-sized businesses, made by Draytek. These routers provide routing, firewall, VPN, content-filtering, bandwidth management, LAN (local area network), and multi-WAN (wide area network) features. Draytek uses proprietary firmware, DrayOS, on the Vigor router line. The DrayOS features EasyVPN and LAN Web Administrator facilitate easy setup for administrators. EasyVPN simplifies the setup of secure VPN connections. LAN Web Administrator provides a browser-based user interface for router management. When a user interacts with the LAN Web Administration interface, the user interface elements trigger actions that generate HTTP requests to interact with the local server. This process contains an uninitialized variable. Due to the uninitialized variable, an unauthenticated attacker could perform memory corruption on the router via specially crafted HTTP requests to hijack execution or inject malicious payloads. If EasyVPN is enabled, the flaw could be remotely exploited through the VPN interface.
EPSS 0.07% · 20.6th percentile
Risk Scores
Timeline
- Sep 16, 2025 CVE ID Reserved
- Oct 2, 2025 PoC Published
- Oct 3, 2025 EPSS Score
- Oct 3, 2025 Coalition ESS Score
- Oct 3, 2025 PoC Published
- Oct 3, 2025 CVE Published
- Oct 3, 2025 PoC Published
- Oct 3, 2025 PoC Published
- Oct 3, 2025 PoC Published
- Oct 4, 2025 PoC Published
- Oct 5, 2025 PoC Published
- Oct 6, 2025 Coalition ESS Score