Many Internet users in Vietnam who are using Internet transmission services of FPT, VNPT and Viettel with DrayTek routers with the codes Vigor 3960/2962/2925, 2865/2866 series and some other models, since the morning of March 23, said they have encountered problems with losing WAN connection, not being assigned IP and causing interruption of Internet access. At the same time, many businesses using these router lines are also experiencing the same situation.

Vigor2866
Vigor 2866, one of the faulty DrayTek router lines. Photo: An Phat

This incident has seriously affected users, causing disruptions in work and even business operations.

Mr. NH, the owner of a computer room providing Internet services in Thu Duc, Ho Chi Minh City, said that the computer room uses router 2925. Since the morning of March 23, the network system has been constantly unstable. Although he has restarted the device many times, the problem has not been resolved. When he went online to find out, he found out that many people had the same problem as him. He had to follow the instructions of the technical team, and everything returned to normal.

Mr. TN, a DrayTek Vigor 2925 user for more than 5 years in Ho Chi Minh City, also said that since the morning of March 23, he saw the IP camera in his house continuously reporting a loss of connection. When he went to the DrayTek administration page, the Uptime section reported that it would be disconnected after about 5 minutes, and the longest was only about 1 hour.

In response to complaints from users and businesses, An Phat Company, the official distributor of DrayTek in Vietnam, has also sent customers a notice about this incident.

According to the distributor's announcement, this is a serious security incident disclosed under the identifiers CVE-2024-51138 and CVE-2024-51139; CVE-2024-41335 and CVE-2024-41336; CVE-2024-41339.

These are security vulnerabilities that allow hackers to conduct remote intrusion to illegally access internal network systems; execute malicious code; and take control of devices.

To fix these errors, the distributor said that DrayTek has released a new firmware update to patch the vulnerabilities. Individual users or businesses need to check the current firmware and quickly upgrade to the latest version announced on the company's homepage. Or contact the technical department for update support.

At the same time, the distributor also recommends that customers do not access the router's administration interface from the Internet if not necessary; change the administration password to a strong one and enable two-factor authentication (if available); and monitor warnings from the system and manufacturer.