CVE-2021-20124highunder attackCWE-22

CVE-2021-20124: high-severity vulnerability in Draytek VigorConnect

Published · Updated

88Vexday Risk Score

Patch now. It under exploitation confirmed by CISA and has a working public exploit.

ssvc Actcvss 7.5epss 96%
from disclosure to weapon
Published on NVDOct 13
CISA KEV+1056d
exploitation probability
96%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
Action required by CISAfederal deadline: 2024-09-24

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

In short

A security flaw in Draytek VigorConnect allows attackers to download any file from the system without logging in, potentially exposing sensitive data like passwords and configuration files.

Technical detail

A path traversal vulnerability (CWE-22) in the WebServlet file download endpoint permits unauthenticated arbitrary file retrieval with root-level privileges. Attack requires only HTTP request manipulation; no authentication or special conditions needed. Impact includes unauthorized access to sensitive system files.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

A local file inclusion vulnerability exists in Draytek VigorConnect 1.6.0-B3 in the file download functionality of the WebServlet endpoint. An unauthenticated attacker could leverage this vulnerability to download arbitrary files from the underlying operating system with root privileges.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N