ZeroHour

CVE-2021-20123

KEV PoC niche

Unauthenticated Path Traversal File Download in DrayTek VigorConnect

CISA: Draytek VigorConnect Path Traversal Vulnerability

CVSS 3.1
7.5 high
EPSS
90%p100
Published
()
KEV added
AI analysis

DrayTek VigorConnect 1.6.0-B3 contains a path traversal/local file inclusion flaw (CWE-22) in the file download functionality of its DownloadFileServlet endpoint. An unauthenticated attacker can send a crafted request with directory-traversal sequences to that endpoint, escaping the intended download path. Successful exploitation allows the attacker to read arbitrary files from the underlying operating system with root privileges, potentially exposing configuration, credentials, and key material. Any organization running the affected version of VigorConnect — DrayTek's on-premises network management suite — is exposed, especially where the web interface is reachable from untrusted networks. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2024-09-03, news reports describe active exploitation hitting DrayTek products, and EPSS assigns a 90.2% probability of exploitation within 30 days (100th percentile).

What to do: Upgrade VigorConnect beyond 1.6.0-B3 to the latest vendor release per DrayTek's instructions, or discontinue use of the product if mitigations are unavailable, as required by the CISA KEV listing. Until patched, restrict access to the VigorConnect web interface, including the DownloadFileServlet endpoint, to trusted management networks via firewall rules or VPN. Also check exposed instances for signs that sensitive files (e.g., password files or private keys) were retrieved, and rotate any credentials accessible to the host.

Affected
DrayTek VigorConnect1.6.0-B3 (broader affected and fixed version ranges not specified in the available data)
Estimated exposure
nichelikely hundreds of on-prem deployments, plausibly up to a few thousand; exact counts unknown — No public install counts exist for VigorConnect, which is DrayTek's relatively small on-prem management suite adopted by only a subset of DrayTek router customers (the VigorACS platform carries the larger install base), and many…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A local file inclusion vulnerability exists in Draytek VigorConnect 1.6.0-B3 in the file download functionality of the DownloadFileServlet endpoint. An unauthenticated attacker could leverage this vulnerability to download arbitrary files from the underlying operating system with root privileges.

CISA Known Exploited Vulnerability
Affected
DrayTek VigorConnect
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
draytek
Products
vigorconnect
Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news