Junglewise Threat Intelligence

CVE-2021-20123: Draytek VigorConnect Path Traversal Vulnerability

CVE-2021-20123 · Severity: critical · CVSS 7.5 · Exploited in the wild · Published 2024-09-03

Vendors: DrayTek.

Executive brief

DrayTek VigorConnect contains a path traversal vulnerability in the DownloadFileServlet endpoint. An unauthenticated remote attacker can exploit this to download arbitrary files from the underlying operating system with root privileges.

Affected products

  • DrayTek VigorConnect 1.6.0-B3

Timeline

  • 2021-10-13: disclosed: NVD Published Date
  • 2024-09-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2024-09-03: exploited: Reported as exploited in the wild by CISA

Related threats