DrayTek UK Users' Community Forum
Help, Advice and Solutions from DrayTek Users
Critical Firmware Release
- qwaz01
- Topic Author
- Offline
- Member
Less
More
- Posts: 116
- Thank yous received: 1
04 Jan 2017 10:07 #87642
by qwaz01
Critical Firmware Release was created by qwaz01
Does anyone have any information regarding the critical firmware release for almost all DrayTek routers? The fact they have released updates for even the old v2820 makes me think it must be a big issue.
The firmware notes only say the following...
Security improvements including one or more considered critical.
Any ideas? Just wondering how big an issue it is?
The firmware notes only say the following...
Security improvements including one or more considered critical.
Any ideas? Just wondering how big an issue it is?
Please Log in or Create an account to join the conversation.
- admin
- Offline
- Site Admin
Less
More
- Posts: 1723
- Thank yous received: 0
04 Jan 2017 10:37 #87643
by admin
Forum Administrator
Replied by admin on topic Re: Critical Firmware Release
Well, I'd say it shouldn't make any different to your actions so it's somewhat moot; if it says 'critical', upgrade...and if it's a big bug, them telling people what it is makes people (who don't upgrade) less secure because most people don't read newsletters, check for new f/w etc, or even go into their WUI ever!
Forum Administrator
Please Log in or Create an account to join the conversation.
- sjltech.uk
- Offline
- Junior Member
Less
More
- Posts: 99
- Thank yous received: 0
04 Jan 2017 11:24 #87646
by sjltech.uk
Replied by sjltech.uk on topic Re: Critical Firmware Release
Just applied the latest firmware to a pair of 2952s running in HA (hot-standby) mode and it breaks things !
To be specific, I have all of the DoS options enabled, and if "Enable ICMP flood defense" is enabled, the routers go into a continuous reboot loop.
Will report this back to Draytek - bit disappointed 'cos I've been beta testing firmware for precisely this issue (and the last beta I had resolved it)
Also, the "Force Router to use DNS server..." in LAN >> General Setup STILL doesn't have an option to select the LAN (again, reported several times in testing)
Cheers
Simon
PS Might post a separate post for the 2952 issue specific to the new firmware
To be specific, I have all of the DoS options enabled, and if "Enable ICMP flood defense" is enabled, the routers go into a continuous reboot loop.
Will report this back to Draytek - bit disappointed 'cos I've been beta testing firmware for precisely this issue (and the last beta I had resolved it)
Also, the "Force Router to use DNS server..." in LAN >> General Setup STILL doesn't have an option to select the LAN (again, reported several times in testing)
Cheers
Simon
PS Might post a separate post for the 2952 issue specific to the new firmware
Please Log in or Create an account to join the conversation.
- qwaz01
- Topic Author
- Offline
- Member
Less
More
- Posts: 116
- Thank yous received: 1
04 Jan 2017 11:45 #87649
by qwaz01
I agree, just wondered if its something that affects every router out of the box or only routers that then have a specific feature enabled, sometimes security flaws can be very niche.
Replied by qwaz01 on topic Re: Critical Firmware Release
Well, I'd say it shouldn't make any different to your actions so it's somewhat moot; if it says 'critical', upgrade...and if it's a big bug, them telling people what it is makes people (who don't upgrade) less secure because most people don't read newsletters, check for new f/w etc, or even go into their WUI ever!admin wrote:
I agree, just wondered if its something that affects every router out of the box or only routers that then have a specific feature enabled, sometimes security flaws can be very niche.
Please Log in or Create an account to join the conversation.
- aweaton
- Offline
- Junior Member
Less
More
- Posts: 76
- Thank yous received: 0
05 Jan 2017 15:33 #87673
by aweaton
Personally I don't really buy that. It is not difficult for malicious groups to reverse engineer the differences between firmware codes.
Industry best practice is to advise what the issue is and offer a patch/fix. DrayTek have done the latter but not the former.
DrayTek products are not cheap consumer devices and business customers expect more information before applying firmware updates.
Replied by aweaton on topic Re: Critical Firmware Release
Well, I'd say it shouldn't make any different to your actions so it's somewhat moot; if it says 'critical', upgrade...and if it's a big bug, them telling people what it is makes people (who don't upgrade) less secure because most people don't read newsletters, check for new f/w etc, or even go into their WUI ever!admin wrote:
Personally I don't really buy that. It is not difficult for malicious groups to reverse engineer the differences between firmware codes.
Industry best practice is to advise what the issue is and offer a patch/fix. DrayTek have done the latter but not the former.
DrayTek products are not cheap consumer devices and business customers expect more information before applying firmware updates.
Please Log in or Create an account to join the conversation.
- aweaton
- Offline
- Junior Member
Less
More
- Posts: 76
- Thank yous received: 0
06 Jan 2017 08:22 #87681
by aweaton
Replied by aweaton on topic Re: Critical Firmware Release
So I bit the bullet and upgraded anyway as the upgrade is deemed critical.
Feedback so far:
- Upgrade was carried out no issue
- large overnight traffic (>40GB) over router based VPN successful. Completed 2 hours before the following issue occurred.
- this morning between 5:31am and 7:03am the router repeatedly lost WAN1 (VDSL2) connection every 3 minutes. Could be coincidental but appeared to be resolved after a hard reboot.
I will keep an eye on this.
Feedback so far:
- Upgrade was carried out no issue
- large overnight traffic (>40GB) over router based VPN successful. Completed 2 hours before the following issue occurred.
- this morning between 5:31am and 7:03am the router repeatedly lost WAN1 (VDSL2) connection every 3 minutes. Could be coincidental but appeared to be resolved after a hard reboot.
I will keep an eye on this.
Please Log in or Create an account to join the conversation.
Moderators: Chris
Copyright © 2025 DrayTek