CVE-2021-20126: CSRF
Draytek VigorConnect 1.6.0-B3 lacks cross-site request forgery protections and does not sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Draytek VigorConnect vulnerability?
The vulnerability ID for this Draytek VigorConnect vulnerability is CVE-2021-20126.
What is the severity of CVE-2021-20126?
The severity of CVE-2021-20126 is high, with a severity value of 8.8.
What is the affected software for CVE-2021-20126?
The affected software for CVE-2021-20126 is Draytek VigorConnect 1.6.0-B3.
What is the description of CVE-2021-20126?
CVE-2021-20126 refers to Draytek VigorConnect 1.6.0-B3 lacking cross-site request forgery protections and insufficiently verifying user-submitted requests.
Is there a fix available for CVE-2021-20126?
To fix CVE-2021-20126, it is recommended to update to a version of Draytek VigorConnect that includes cross-site request forgery protections and proper request verification.