peter bassill · operator
$ cve CVE-2021-20123 JSON

CVE-2021-20123 KEV

7.5
HIGH · CVSS 3.1 · EPSS 90.2% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2024-09-24.

Description

A local file inclusion vulnerability exists in Draytek VigorConnect 1.6.0-B3 in the file download functionality of the DownloadFileServlet endpoint. An unauthenticated attacker could leverage this vulnerability to download arbitrary files from the underlying operating system with root privileges.

Scoring

CVSS7.5 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS90.23% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-22
On CISA KEVyes — remediate by 2024-09-24
Public exploitnone known
Published2021-10-13
Last modified2026-06-17

CISA KEV

NameDraytek VigorConnect Path Traversal Vulnerability
Added2024-09-03
Due2024-09-24
Vendor / productDrayTek / VigorConnect
Ransomware usenone reported

Affected (1)

VendorProduct
draytekvigorconnect

References

→ the Explorer  ·  watch your stack  ·  NVD