Page 1 of 1

DrayOS Router Flaw Allows Remote Code Execution by Attackers

Posted: Sun Oct 05, 2025 4:36 am
by Shane1145
A critical vulnerability affecting DrayOS routers could let unauthenticated attackers execute code remotely.

Discovered on July 22 by Pierre-Yves Maes of ChapsVision, the flaw stems from the use of an uninitialized variable in the Web User Interface (WebUI).

Crafting special HTTP or HTTPS requests to the WebUI triggers memory corruption, potentially crashing the device or allowing remote code execution in specific scenarios.

https://gbhackers.com/drayos-router-flaw/