Executive brief
DrayTek VigorConnect contains a path traversal vulnerability in the WebServlet endpoint's file download functionality. An unauthenticated remote attacker can exploit this to download arbitrary files from the underlying operating system with root privileges.
Affected products
- DrayTek VigorConnect 1.6.0-B3
Timeline
- 2021-10-13: disclosed
- 2024-09-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2024-09-03: exploited