CVE-2021-20124
Description
A local file inclusion vulnerability exists in Draytek VigorConnect 1.6.0-B3 in the file download functionality of the WebServlet endpoint. An unauthenticated attacker could leverage this vulnerability to download arbitrary files from the underlying operating system with root privileges.
Summary dbcve.org
A local file inclusion vulnerability exists in Draytek VigorConnect 1.6.0-B3 in the file download functionality of the WebServlet endpoint. An unauthenticated attacker can exploit this vulnerability to download arbitrary files from the underlying operating system with root privileges by manipulating file path parameters in the request.
Mitigation
Apply vendor patches when available. In the interim, implement a WAF with path traversal detection rules, restrict network access to the management interface, and consider network segmentation to limit exposure.