WARNING: Emerging critical issue affecting Draytek routers - update firmware as soon as possible

Incident Report for Art Of Automation

Resolved

This incident has been resolved.
Posted Mar 28, 2025 - 17:01 CET

Monitoring

Draytek published a support document on Monday regarding this incident, providing guidance on addressing the router reboot issues:
https://faq.draytek.com.au/docs/draytek-routers-rebooting-how-to-solve-this-issue/

Bleepingcomputer also published an article about the Draytek issue with additional information and a workaround if patching is not possible:
https://www.bleepingcomputer.com/news/security/draytek-routers-worldwide-go-into-reboot-loops-over-weekend/

We will keep this warning on our status page until Saturday March 29th and urge all customers who use Draytek equipment in their networks to update the firmware as soon as possible.
Posted Mar 24, 2025 - 22:17 CET

Identified

Usually we only use this statuspage to inform you regarding incidents affecting our own services, but for this message, we’re making an exception to inform as many customers as possible.

Draytek routers are rebooting automatically and unexpectedly, or stop processing internet traffic from time to time. At the time of writing this warning, Draytek has not officially responded yet, but we notice reports coming in from Draytek customers and ISPs on a global scale.

Art Of Automation is not using any Draytek equipment within our own infrastructure, nor do we sell or support devices from Draytek. However, we are aware of the fact that some customers are using Draytek routers in their own networks.

Art Of Automation Managed Services customers are not affected by this issue, because we don’t use or support Draytek equipment in managed infrastructure either. This warning only applies to customers using our Internet Services as a standalone product.

There is no clear/official root cause yet, but for now we know that the routers that are affected have not been patched recently and/or are EOL for some time. It seems that known Draytek vulnerabilities are actively being exploited, resulting in degraded performance and critical security risks for your internal network. Therefore we recommend our customers, if you’re using Draytek equipment, to update the firmware as soon as possible:

https://www.draytek.com/about/security-advisory/
https://www.draytek.com/about/security-advisory/buffer-overflow-vulnerabilities-(cve-2024-51138-cve-2024-51139)
https://www.draytek.com/about/security-advisory/denial-of-service,-information-disclosure,-and-code-execution-vulnerabilities

For additional information, please review the following:

https://isc.sans.edu/diary/Mirai+Bot+now+incroporating+malformed+DrayTek+Vigor+Router+Exploits/31770/
https://www.bleepingcomputer.com/news/security/draytek-fixed-critical-flaws-in-over-700-000-exposed-routers/
https://www.forescout.com/blog/draytek-routers-exploited-in-massive-ransomware-campaign-analysis-and-recommendations/
https://www.forescout.com/resources/draybreak-draytek-research/
https://www.ispreview.co.uk/index.php/2025/03/broadband-isps-report-uk-connectivity-problems-with-vulnerable-draytek-routers.html
https://interstatus.co.uk/
https://aastatus.net/42755
Posted Mar 23, 2025 - 18:16 CET
This incident affected: General internet access services and AOA Glasvezel fiber access infrastructure.