When devices are compromised by unauthorised access, it is most commonly due to poor security settings, or not updating the firmware to close off any known security vulnerabilities present in older firmware versions.
The best way to prevent unauthorised access to your device is to keep the firmware up to date, turn off any remote-access services that you don’t use, use a strong password on the device, and if you can, enable Two-Factor Authentication.
You can check for firmware updates in the Web UI of your device, eg. by clicking the Firmware Version link in the System Information panel on the Dashboard page:

Or by checking our website for the latest firmware for your device, and installing it from the System Maintenance >> Firmware upgrade page:

You can disable remote-access management options that you don’t use, and enable brute-force protection to help prevent brute-force password guessing attacks in the System Maintenance >> Management settings.
Recommended settings include enabling the Validation Code on the login page, disabling management from the Internet, Disable PING from the Internet, enable Brute Force Protection, ensure HTTPS is enforced with a minimum of TLS 1.2 or higher encryption:

If you need to access the router remotely, consider using the VPN feature instead of allowing management directly via the Internet, so that you must first connect to the VPN, and then log into the router’s management features. If you must access the device directly via the public Internet instead of through a VPN, consider using the Access List feature to restrict access by only allowing the IP address(es) you need.
You can also disable unused or insecure services, even on your own internal network (LAN).
Recommended settings include allowing only HTTPS instead of insecure HTTP, disabling FTP if not in use, using secure SSH instead of telnet, disabling TR069 if not in use, and restricting even LAN side logins to only a dedicated network / infrastructure management LAN on its own VLAN, if you can. You can also create IP Objects to further restrict LAN-side access to the router:

And of course, using a strong password is essential, but you can also configure more security options on the System Maintenance >> Administrator Password page:
Here, you can change the admin password, and if you must log into your Draytek Vigor router remotely via the Internet without using a VPN connection (and therefore cannot disable management over the Internet), you can enable Advanced Authentication and set up Mobile one-Time Passwords, or Two-Factor Authentication that relies on codes sent to you via SMS and/or email. You might be familiar with this kind of two-factor authentication already if you use any Internet banking services:

You can also create your own Administrator Local User, and then disable the default admin user account from logging into the Web UI from the Internet, so that an unauthorised user would not even know the correct username to try guessing passwords for.
Consider making use of these options to increase the security of your device.
Article published by Shaun C. on 3/10/2024