DrayTek UK Users' Community Forum

Help, Advice and Solutions from DrayTek Users

Vigor 2860 V3.8.5.1 (Krack fix)

  • hornbyp
  • Topic Author
  • User
  • User
More
15 Nov 2017 16:25 #1 by hornbyp
Vigor 2860 V3.8.5.1 (Krack fix) was created by hornbyp
Firmware to fix the WPA2 vulnerability has arrived on the UK download site. http://www.draytek.co.uk/support/downloads

Only for the 2860/2862 at the time of writing (from what I can make out, though I didn't check that closely).

Please Log in or Create an account to join the conversation.

More
15 Nov 2017 19:15 #2 by chrisw
Replied by chrisw on topic Re: Vigor 2860 V3.8.5.1 (Krack fix)
Being an early adopter I installed a few days ago from .com.tw site. Noticed that on the dashboard page (only) after about a minute or so of inactivity I get:

Authorization Error !
Browser not authentication-capable or authentication failed.

No idea what triggers this, but otherwise works fine. I'll flip to the BT version just in case there's a difference [Post flip edit: There is no difference...].

Please Log in or Create an account to join the conversation.

  • hornbyp
  • Topic Author
  • User
  • User
More
15 Nov 2017 23:21 #3 by hornbyp
Replied by hornbyp on topic Re: Vigor 2860 V3.8.5.1 (Krack fix)
Yup - I have the same :cry:

Please Log in or Create an account to join the conversation.

  • adrianh54
  • User
  • User
More
16 Nov 2017 06:47 #4 by adrianh54
Replied by adrianh54 on topic Re: Vigor 2860 V3.8.5.1 (Krack fix)

hornbyp wrote: Yup - I have the same :cry:



This came up in October.


https://forum.draytek.co.uk/viewtopic.php?f=14&t=21902

Please Log in or Create an account to join the conversation.

More
17 Nov 2017 17:25 #5 by admin
Replied by admin on topic Re: Vigor 2860 V3.8.5.1 (Krack fix)

hornbyp wrote: Firmware to fix the WPA2 vulnerability has arrived on the UK download site.



Bear in mind that that the issue applies only to wireless clients or units acting as a client, so not routers which are just acting as your wireless base - you need to update your client devices.

See http://www.draytek.co.uk/information/our-technology/wpa2-krack-vulnerability



Forum Administrator

Please Log in or Create an account to join the conversation.

  • hornbyp
  • Topic Author
  • User
  • User
More
12 Dec 2017 11:48 #6 by hornbyp
Replied by hornbyp on topic Vigor 2860 V3.8.5.2 (additional Krack fix)
This issue seems to have been assessed further, and apparently the disabling of 'EAPOL key retries' seems to greatly mitigate the problem. See https://www.draytek.co.uk/support/guides/kb-wpa2-eapol

This option has been added to 3.8.5.2 (for the 2860) ... and is currently available from: https://www.draytek.com/en/download/firmware/vigor2860-series/

(corrected URL - no idea why Draytek removed the old one...)

Please Log in or Create an account to join the conversation.