• About
  • Subscribe
  • Contact
Friday, May 9, 2025
    Login
FutureCISO
  • People
  • Process
  • Technology
  • Resources
    • White Papers
    • PodChats
No Result
View All Result
  • People
  • Process
  • Technology
  • Resources
    • White Papers
    • PodChats
No Result
View All Result
FutureCISO
No Result
View All Result
Home Process Compliance and Governance

Routers still a popular vector attack

FutureCISO Editors by FutureCISO Editors
October 3, 2024
Routers still a popular vector attack

Image from Forescout Technologies

Share on FacebookShare on Twitter

In February 2016, US$951 million was siphoned off the Bangladesh Bank by way of an unprotected router. You could be next warns a new report.

The "DRAY:BREAK" Research Report by Forescout Technologies, reveals 14 previously unknown vulnerabilities in DrayTek routers, including one with a critical severity rating of 10. These vulnerabilities could allow attackers to take full control of the devices, leading to potential ransomware attacks, data exfiltration, and denial-of-service incidents. The widespread use of DrayTek routers across various industries makes them prime targets for cybercriminals.

"Routers are crucial for keeping internal systems connected to the outside world yet too many organizations overlook their security until they are exploited by attackers,” stated Barry Mainz, CEO of Forescout. He emphasised that cybercriminals actively seek weaknesses in router defences, using them to infiltrate networks and steal sensitive information.

The report highlights that over 704,000 DrayTek routers are currently exposed to the internet, with a significant number located in the UK, EU, and Asia. Nearly 40% of these routers remain vulnerable to issues identified two years ago and listed by the Cybersecurity and Infrastructure Security Agency (CISA). Additionally, the vulnerabilities impact 24 router models, with 11 categorized as end-of-life (EoL), complicating efforts to patch them.

Forescout's findings also detail potential attack scenarios. Vulnerabilities in DrayTek routers could allow attackers to deploy persistent rootkits, intercept network traffic, and move laterally within a network. High-performance models, like the Vigor3910, could be repurposed as command-and-control servers, facilitating further attacks.

In response to the findings, DrayTek has patched all identified firmware vulnerabilities. However, organisations are urged to take additional mitigation steps. "To safeguard against these vulnerabilities, organizations must immediately patch affected DrayTek devices with the latest firmware," advised Daniel dos Santos, Head of Security Research at Forescout. He recommended disabling unnecessary remote access, implementing access control measures, and monitoring network activity to enhance security.

Related:  Forescout unveils All-in-One OT security solution for diverse environments

Recommended actions

Source: Forescout Technologies 2024
  1. Identify DrayTek routers on your network and the firmware version they run
  2. Patch: ensure you have applied the latest firmware updates to mitigate vulnerabilities
  3. Identify End-of-Life (EOL) routers and consider replacing them
  4. Disable Remote Access: consider disabling remote access capabilities when they are not required, to reduce exposure
  5. Mitigate Risks: Enable access control lists, multi-factor authentication, and syslog logging
Tags: CISO action itemsDrayTek routersForescout Technologiesvulnerabilities
FutureCISO Editors

FutureCISO Editors

No Result
View All Result

Recent Posts

  • DDoS attacks surge in Asia Pacific, claims Cloudflare
  • Reimagining security for the AI Era
  • PodChats for FutureCISO: Articulating the business value of security in 2025
  • New standard for cybersecurity at the storage layer
  • Cybersecurity challenges persist despite improved defenses

Categories

  • Blogs
  • Compliance and Governance
  • Culture and Behaviour
  • Cybersecurity careers
  • Data Protection
  • Endpoint Security
  • Incident Response
  • Network Security
  • People
  • Process
  • Resources
  • Risk Management
  • Technology
  • Training and awarenes
  • Videos
  • Webinars and PodChats
  • White Papers

Strategic Insights for Chief Information Officers

FutureCISO serves the interests of the Chief Information Security Officer (CISO) and the information security profession. Its purpose is to provide relevant and timely industry insights around all things important to security professionals and organisations that recognize and value the importance of protecting the organisation’s data and its customers’ privacy.

Cxociety Media Brands

  • FutureIoT
  • FutureCFO
  • FutureCIO

Categories

  • Privacy Policy
  • Terms of Use
  • Cookie Policy

Copyright © 2024 Cxociety Pte Ltd | Designed by Pixl

Login to your account below

or

Not a member yet? Register here

Forgotten Password?

Fill the forms bellow to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • People
  • Process
  • Technology
  • Resources
    • White Papers
    • PodChats
Login

Copyright © 2024 Cxociety Pte Ltd | Designed by Pixl