CVE-2021-20125: Path Traversal
An arbitrary file upload and directory traversal vulnerability exists in the file upload functionality of DownloadFileServlet in Draytek VigorConnect 1.6.0-B3. An unauthenticated attacker could leverage this vulnerability to upload files to any location on the target operating system with root privileges.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-20125?
CVE-2021-20125 is an arbitrary file upload and directory traversal vulnerability in the file upload functionality of Draytek VigorConnect 1.6.0-B3.
How severe is CVE-2021-20125?
CVE-2021-20125 has a severity rating of 9.8 (critical).
How does CVE-2021-20125 affect Draytek VigorConnect 1.6.0-B3?
CVE-2021-20125 allows unauthenticated attackers to upload files to any location on the target operating system with root privileges.
How can I fix CVE-2021-20125?
To fix CVE-2021-20125, apply the latest security patches or updates provided by Draytek.
Where can I find more information about CVE-2021-20125?
You can find more information about CVE-2021-20125 at the following link: [https://www.tenable.com/security/research/tra-2021-42]