DrayTek Vigor
DrayTek
Actively exploited vulnerabilities
The US cybersecurity agency CISA lists these vulnerabilities in its catalog of Known Exploited Vulnerabilities. Check your version and patch or mitigate promptly.
- CVE-2020-8515Multiple DrayTek Vigor Routers Web Management Page Vulnerability
9.8 critical · over the network, without login · CISA deadline was 3 May 22
- CVE-2020-15415DrayTek Multiple Vigor Routers OS Command Injection Vulnerability
9.8 critical · over the network, without login · CISA deadline was 21 Oct 24
- CVE-2024-12987DrayTek Vigor Routers OS Command Injection Vulnerability
9.8 critical · over the network, without login · CISA deadline was 5 Jun 25
Source: CISA KEV. The CVE is matched to the product automatically — when in doubt, the linked NVD entry applies.
BSI security advisories
Advisories the German BSI (CERT-Bund) published for this product. Whether your version is affected is stated in the advisory itself.
- DrayTek Vigor Switches: Mehrere Schwachstellen ermöglichen Codeausführung
WID-SEC-W-2026-2991 · 25 Aug
- DrayTek VigorAP: Mehrere Schwachstellen ermöglichen Codeausführung
WID-SEC-W-2026-2990 · 25 Aug
Version history & changelog · as detected by patchletter
No releases recorded yet — the source was just added.
Never miss a DrayTek Vigor update
We check the source daily and email you — instantly or as a digest. Free, one-click unsubscribe.
Watch DrayTek VigorEmbed this badge
Shows the current DrayTek Vigor version and updates itself. Free to use, no account needed.
[](https://patchletter.com/en/software/draytek-vigor)https://patchletter.com/badge/draytek-vigor.svgAlso available: ?v=eol (end of support) and ?v=cve (actively exploited).