Junglewise Threat Intelligence

CVE-2021-20124: Draytek VigorConnect Path Traversal Vulnerability

CVE-2021-20124 · Severity: critical · CVSS 7.5 · Exploited in the wild · Published 2024-09-03

Vendors: DrayTek.

Executive brief

DrayTek VigorConnect contains a path traversal vulnerability in the WebServlet endpoint's file download functionality. An unauthenticated remote attacker can exploit this to download arbitrary files from the underlying operating system with root privileges.

Affected products

  • DrayTek VigorConnect 1.6.0-B3

Timeline

  • 2021-10-13: disclosed
  • 2024-09-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2024-09-03: exploited

Related threats