CVE-2025-44643
8.6Draytek · AP903, AP912C, AP918R
Certain Draytek access points contain a hardcoded weak password in the ripd.conf configuration file, allowing unauthenticated attackers to gain control over the routing daemon.
Executive summary
A high-severity insecure configuration vulnerability in multiple Draytek access points allows unauthenticated attackers to compromise the routing daemon and intercept network traffic.
Vulnerability
The vulnerability stems from a hardcoded weak password within the ripd.conf file, which governs the routing daemon. An unauthenticated attacker with network access can leverage this hardcoded credential to bypass authentication and gain unauthorized control over the routing process.
Business impact
The ability for an attacker to gain control over the routing daemon poses a significant risk to network integrity and confidentiality. By manipulating network routes or intercepting traffic, an attacker could facilitate man-in-the-middle attacks, exfiltrate sensitive data, or cause a denial of service. With a CVSS score of 8.6, this vulnerability represents a high-risk security flaw that could lead to full compromise of the local network segment.
Remediation
Immediate Action: Contact Draytek support or monitor the official vendor security advisory portal to identify and apply the specific firmware patch once released for the affected models.
Proactive Monitoring: Review network access logs for suspicious administrative activity or unusual routing table changes originating from these access points.
Compensating Controls: Restrict network access to the management interfaces of these devices by placing them on a dedicated, isolated management VLAN and implementing firewall rules to block unauthorized traffic.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the high CVSS score and the nature of the vulnerability, administrators must prioritize the protection of these devices. Until a vendor-supplied firmware update is verified and applied, it is critical to implement network-level access controls to minimize the attack surface and prevent unauthorized access to the affected routing daemon.