Executive brief
DrayTek VigorConnect contains a path traversal vulnerability in the DownloadFileServlet endpoint. An unauthenticated remote attacker can exploit this to download arbitrary files from the underlying operating system with root privileges.
Affected products
- DrayTek VigorConnect 1.6.0-B3
Timeline
- 2021-10-13: disclosed: NVD Published Date
- 2024-09-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2024-09-03: exploited: Reported as exploited in the wild by CISA