Brand profile · models not graded yet

Is DrayTek Safe?

DrayTek is a Taiwanese router maker with five flaws in CISA's exploited catalog and a 2025 attack wave on unpatched routers. Full security analysis.

Last reviewed: October 2026 · ismyroutersafe.com

Ownership & FCC Status
Owner
DrayTek Corporation (Hsinchu, Taiwan)
FCC Status
Not on the Covered List; no Conditional Approval. Existing authorized models can still be sold and updated
Ban Status
Not banned. Not named on the FCC Covered List
Manufacturing
Not confirmed
Models graded
Not yet

Security Verdict

DrayTek is a Taiwanese maker of small-business and prosumer routers, sold mostly through resellers and business ISPs in the UK and Europe. CISA lists five DrayTek vulnerabilities as actively exploited, and a 2024 FBI/NSA advisory named DrayTek flaws among those used by a China-linked botnet of more than 260,000 devices. In March 2025, attacks on unpatched DrayTek routers with remote management or SSL VPN exposed caused reboot loops for customers of several UK ISPs. DrayTek has shipped patches, including for some end-of-life models, but some older models had no patch.

Bottom line: DrayTek routers are a frequent, proven target. If you run one, keep firmware current, turn off remote management and SSL VPN unless you need them, and replace models that no longer get patches.

Rio Router
From the team behind this checker
Weighing up DrayTek? See the router that scores an A on this same method.
  • SecureRooms. Smart devices live apart from your computers.
  • You approve every new device before it joins.
  • Rio VPN built in. First year included.
  • Set up in about 10 minutes from the app.
See Rio Router →
$199.99 · 1 year of VPN included, then $7.99/mo · 30-day returns · 1-year warranty. Rio builds this site, and its router is graded by the same method as every other.

Corporate Ownership Structure

DrayTek Corporation is headquartered in Hsinchu, Taiwan, and led by founder and CEO Calvin Ma. No state ownership links were found. Its routers are sold mainly through resellers and business ISPs, especially in the UK and Europe.

Key Risk Factors

Five vulnerabilities on CISA's exploited list
CISA's Known Exploited Vulnerabilities catalog lists CVE-2024-12987, CVE-2020-15415, CVE-2021-20123, CVE-2021-20124 and CVE-2020-8515.
Used by a China-linked botnet
A September 2024 FBI, Cyber National Mission Force and NSA advisory on the Flax Typhoon botnet (260,000+ devices) listed three DrayTek flaws among those exploited, including one in the Vigor2960, which is no longer supported.
2025 attack wave knocked UK routers offline
In March 2025, DrayTek reported repeated, suspicious connection attempts against unpatched routers with SSL VPN or remote management exposed. Customers of UK ISPs including Gamma, Zen and Andrews & Arnold saw reboot loops. Some old models, such as the Vigor 2110 and 2710, had no patch.
Large exposed footprint
Forescout's 2024 DRAY:BREAK research found 14 flaws in DrayTek firmware. At the time, roughly 704,000 to 752,000 DrayTek devices were estimated to be exposed to the internet.
Patches reach some end-of-life models
Censys reported that DrayTek released DRAY:BREAK fixes for all affected models, including end-of-life units such as the Vigor2620 and VigorLTE200. DrayTek also issued VigorAP and VigorSwitch fixes in August 2026.

Known CVEs - DrayTek Routers

The following vulnerabilities from the NIST National Vulnerability Database affect DrayTek router models. This is a representative sample; the full CVE list may be longer.

CVE-2024-12987 High (CVSS 7.3)
OS command injection in the Vigor2960, Vigor300B and Vigor3900 web interface. Actively exploited (CISA KEV).
CVE-2024-41592 High (CVSS 8)
Buffer overflow in the Vigor web interface, part of the 2024 DRAY:BREAK set of 14 flaws.
CVE-2024-41593 Critical (CVSS 9.8)
Remote code execution in the Vigor310 through firmware 4.3.2.6.
CVE-2026-71914 Critical (CVSS 9.8)
Command injection in VigorAP access points through a UDP management service.

Frequently Asked Questions

DrayTek routers are only as safe as their firmware. DrayTek has five vulnerabilities on CISA's actively exploited list, its routers were named in a 2024 FBI/NSA botnet advisory, and unpatched units were hit by attacks in 2025. A fully patched DrayTek with remote management and SSL VPN turned off is far less exposed. Older models with no patch should be replaced.

No. DrayTek is not named on the FCC Covered List and does not hold an FCC Conditional Approval. Under the March 2026 FCC rule, new foreign-produced consumer and small-business routers need a Conditional Approval to be authorized. Models already authorized can still be sold, used and updated.

DrayTek Corporation, a Taiwanese company based in Hsinchu, led by founder and CEO Calvin Ma. Where its routers are manufactured is not publicly confirmed.

In March 2025, unpatched DrayTek routers with SSL VPN or remote management exposed went into reboot loops, affecting customers of several UK ISPs. DrayTek called it the first confirmed in-the-wild use of an exploit against these routers and said firmware from around 2020 onward fixed it. Some old models had no fix.

Yes. DrayTek publishes security advisories and released fixes for the 2024 DRAY:BREAK flaws, including for some end-of-life models. It issued further VigorAP and VigorSwitch fixes in August 2026. Its automatic-update default and formal end-of-life policy are not publicly confirmed.

Sources

Facts on this page come from these sources (publish date, or the date we checked the page).

CHECK YOUR SPECIFIC MODEL

Get your router's full security report

Check any specific model for CVEs, FCC status, security capabilities, and your personalized action plan.

Check a Router → Top 10 Safe Routers
Most home routers have hidden risks. Rio Router is the only one we rate A. See why →