CVE-2021-20123: high-severity vulnerability in Draytek VigorConnect
Published · Updated
Patch now. It under exploitation confirmed by CISA and has a working public exploit.
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
An unauthenticated attacker can download any file from a DrayTek VigorConnect server by exploiting a flaw in the file download feature, potentially exposing sensitive system files. This is critical because no login is required and the attacker gains access to files with the highest privilege level.
A path traversal vulnerability in DownloadFileServlet (CWE-22) allows unauthenticated remote attackers to bypass directory restrictions and retrieve arbitrary files with root-level permissions. The vulnerability stems from insufficient input validation in the file download mechanism, enabling an attacker to manipulate file paths and access sensitive system resources.
The full analysis of this CVE is available in Portuguese →