CVE-2021-20123highunder attackCWE-22

CVE-2021-20123: high-severity vulnerability in Draytek VigorConnect

Published · Updated

88Vexday Risk Score

Patch now. It under exploitation confirmed by CISA and has a working public exploit.

ssvc Actcvss 7.5epss 90%
from disclosure to weapon
Published on NVDOct 13
CISA KEV+1056d
exploitation probability
90%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
Action required by CISAfederal deadline: 2024-09-24

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

In short

An unauthenticated attacker can download any file from a DrayTek VigorConnect server by exploiting a flaw in the file download feature, potentially exposing sensitive system files. This is critical because no login is required and the attacker gains access to files with the highest privilege level.

Technical detail

A path traversal vulnerability in DownloadFileServlet (CWE-22) allows unauthenticated remote attackers to bypass directory restrictions and retrieve arbitrary files with root-level permissions. The vulnerability stems from insufficient input validation in the file download mechanism, enabling an attacker to manipulate file paths and access sensitive system resources.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

A local file inclusion vulnerability exists in Draytek VigorConnect 1.6.0-B3 in the file download functionality of the DownloadFileServlet endpoint. An unauthenticated attacker could leverage this vulnerability to download arbitrary files from the underlying operating system with root privileges.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N