HIGH

CVE-2021-20124

Draytek Vigorconnect 2021-10-13 CVSS v3.1
CVSS
7.5
KEV

Description

A local file inclusion vulnerability exists in Draytek VigorConnect 1.6.0-B3 in the file download functionality of the WebServlet endpoint. An unauthenticated attacker could leverage this vulnerability to download arbitrary files from the underlying operating system with root privileges.

Summary dbcve.org

A local file inclusion vulnerability exists in Draytek VigorConnect 1.6.0-B3 in the file download functionality of the WebServlet endpoint. An unauthenticated attacker can exploit this vulnerability to download arbitrary files from the underlying operating system with root privileges by manipulating file path parameters in the request.

Mitigation

Apply vendor patches when available. In the interim, implement a WAF with path traversal detection rules, restrict network access to the management interface, and consider network segmentation to limit exposure.

Proof of Concept

Weakness (CWE)

CWE-22 Path Traversal

EPSS Score

96.31%
Probability of exploitation in next 30 days
99.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE