CVE-2021-20124: Draytek VigorConnect Path Traversal Vulnerability
A local file inclusion vulnerability exists in Draytek VigorConnect 1.6.0-B3 in the file download functionality of the WebServlet endpoint. An unauthenticated attacker could leverage this vulnerability to download arbitrary files from the underlying operating system with root privileges.
Other sources
Draytek VigorConnect contains a path traversal vulnerability in the file download functionality of the WebServlet endpoint. An unauthenticated attacker could leverage this vulnerability to download arbitrary files from the underlying operating system with root privileges.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
If vendor mitigations are unavailable, discontinue use of Draytek VigorConnect 1.6.0-B3.
Event History
Frequently Asked Questions
What is the vulnerability ID for this Draytek VigorConnect vulnerability?
The vulnerability ID for this Draytek VigorConnect vulnerability is CVE-2021-20124.
What is the severity of CVE-2021-20124?
The severity of CVE-2021-20124 is high with a CVSS score of 7.5.
What is the affected software for CVE-2021-20124?
The affected software for CVE-2021-20124 is Draytek VigorConnect 1.6.0-Beta3.
What is the description of CVE-2021-20124?
CVE-2021-20124 is a local file inclusion vulnerability in Draytek VigorConnect 1.6.0-B3. An unauthenticated attacker could download arbitrary files from the underlying operating system with root privileges.
Is authentication required to exploit CVE-2021-20124?
No, CVE-2021-20124 can be exploited by an unauthenticated attacker.