Is DrayTek Safe?
DrayTek is a Taiwanese router maker with five flaws in CISA's exploited catalog and a 2025 attack wave on unpatched routers. Full security analysis.
DrayTek is a Taiwanese router maker with five flaws in CISA's exploited catalog and a 2025 attack wave on unpatched routers. Full security analysis.
DrayTek is a Taiwanese maker of small-business and prosumer routers, sold mostly through resellers and business ISPs in the UK and Europe. CISA lists five DrayTek vulnerabilities as actively exploited, and a 2024 FBI/NSA advisory named DrayTek flaws among those used by a China-linked botnet of more than 260,000 devices. In March 2025, attacks on unpatched DrayTek routers with remote management or SSL VPN exposed caused reboot loops for customers of several UK ISPs. DrayTek has shipped patches, including for some end-of-life models, but some older models had no patch.
Bottom line: DrayTek routers are a frequent, proven target. If you run one, keep firmware current, turn off remote management and SSL VPN unless you need them, and replace models that no longer get patches.
DrayTek Corporation is headquartered in Hsinchu, Taiwan, and led by founder and CEO Calvin Ma. No state ownership links were found. Its routers are sold mainly through resellers and business ISPs, especially in the UK and Europe.
The following vulnerabilities from the NIST National Vulnerability Database affect DrayTek router models. This is a representative sample; the full CVE list may be longer.
DrayTek routers are only as safe as their firmware. DrayTek has five vulnerabilities on CISA's actively exploited list, its routers were named in a 2024 FBI/NSA botnet advisory, and unpatched units were hit by attacks in 2025. A fully patched DrayTek with remote management and SSL VPN turned off is far less exposed. Older models with no patch should be replaced.
No. DrayTek is not named on the FCC Covered List and does not hold an FCC Conditional Approval. Under the March 2026 FCC rule, new foreign-produced consumer and small-business routers need a Conditional Approval to be authorized. Models already authorized can still be sold, used and updated.
DrayTek Corporation, a Taiwanese company based in Hsinchu, led by founder and CEO Calvin Ma. Where its routers are manufactured is not publicly confirmed.
In March 2025, unpatched DrayTek routers with SSL VPN or remote management exposed went into reboot loops, affecting customers of several UK ISPs. DrayTek called it the first confirmed in-the-wild use of an exploit against these routers and said firmware from around 2020 onward fixed it. Some old models had no fix.
Yes. DrayTek publishes security advisories and released fixes for the 2024 DRAY:BREAK flaws, including for some end-of-life models. It issued further VigorAP and VigorSwitch fixes in August 2026. Its automatic-update default and formal end-of-life policy are not publicly confirmed.
Facts on this page come from these sources (publish date, or the date we checked the page).
CHECK YOUR SPECIFIC MODEL
Check any specific model for CVEs, FCC status, security capabilities, and your personalized action plan.
Check a Router → Top 10 Safe Routers