Actively exploited vulnerabilities

The US cybersecurity agency CISA lists these vulnerabilities in its catalog of Known Exploited Vulnerabilities. What CISA does not carry does not appear in this list — even where it is being exploited.

  • CVE-2020-8515Multiple DrayTek Vigor Routers Web Management Page Vulnerability

    9.8 critical · over the network, without login · CISA deadline was 3 May 22

  • CVE-2020-15415DrayTek Multiple Vigor Routers OS Command Injection Vulnerability

    9.8 critical · over the network, without login · CISA deadline was 21 Oct 24

  • CVE-2024-12987DrayTek Vigor Routers OS Command Injection Vulnerability

    9.8 critical · over the network, without login · CISA deadline was 5 Jun 25

Source: CISA KEV. The CVE is matched to the product automatically — when in doubt, the linked NVD entry applies.

BSI security advisories

Advisories the German BSI (CERT-Bund) published for this product. Whether your version is affected is stated in the advisory itself.

All BSI advisories →

Version history & changelog · as detected by patchletter

No releases recorded yet — the source was just added.

An email as soon as a new DrayTek Vigor version ships

We reconcile the vendor source daily. When a new version appears, it lands in your inbox right away or bundled as a digest. The update email is free and ends with one click. Alerts about vulnerabilities and end of support are part of patchletter Pro.

Embed this badge

The badge shows the current DrayTek Vigor version and keeps it up to date. Anyone may embed it, no account needed.

DrayTek Vigor badge
[![DrayTek Vigor](https://patchletter.com/badge/draytek-vigor.svg)](https://patchletter.com/en/software/draytek-vigor)
https://patchletter.com/badge/draytek-vigor.svg

Also available: ?v=eol (end of support) and ?v=cve (actively exploited).

Related tools in Network, Switches & Wi-Fi