First published: Wed Oct 13 2021(Updated: )
An arbitrary file upload and directory traversal vulnerability exists in the file upload functionality of DownloadFileServlet in Draytek VigorConnect 1.6.0-B3. An unauthenticated attacker could leverage this vulnerability to upload files to any location on the target operating system with root privileges.
Credit: vulnreport@tenable.com
Affected Software | Affected Version | How to fix |
---|---|---|
Draytek VigorConnect | =1.6.0-beta3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-20125 is an arbitrary file upload and directory traversal vulnerability in the file upload functionality of Draytek VigorConnect 1.6.0-B3.
CVE-2021-20125 has a severity rating of 9.8 (critical).
CVE-2021-20125 allows unauthenticated attackers to upload files to any location on the target operating system with root privileges.
To fix CVE-2021-20125, apply the latest security patches or updates provided by Draytek.
You can find more information about CVE-2021-20125 at the following link: [https://www.tenable.com/security/research/tra-2021-42]