CVE-2021-20124: high-severity vulnerability in Draytek VigorConnect
Published · Updated
Patch now. It under exploitation confirmed by CISA and has a working public exploit.
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
A security flaw in Draytek VigorConnect allows attackers to download any file from the system without logging in, potentially exposing sensitive data like passwords and configuration files.
A path traversal vulnerability (CWE-22) in the WebServlet file download endpoint permits unauthenticated arbitrary file retrieval with root-level privileges. Attack requires only HTTP request manipulation; no authentication or special conditions needed. Impact includes unauthorized access to sensitive system files.
The full analysis of this CVE is available in Portuguese →