CVE-2021-20123
KEV PoC nicheUnauthenticated Path Traversal File Download in DrayTek VigorConnect
CISA: Draytek VigorConnect Path Traversal Vulnerability
DrayTek VigorConnect 1.6.0-B3 contains a path traversal/local file inclusion flaw (CWE-22) in the file download functionality of its DownloadFileServlet endpoint. An unauthenticated attacker can send a crafted request with directory-traversal sequences to that endpoint, escaping the intended download path. Successful exploitation allows the attacker to read arbitrary files from the underlying operating system with root privileges, potentially exposing configuration, credentials, and key material. Any organization running the affected version of VigorConnect — DrayTek's on-premises network management suite — is exposed, especially where the web interface is reachable from untrusted networks. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2024-09-03, news reports describe active exploitation hitting DrayTek products, and EPSS assigns a 90.2% probability of exploitation within 30 days (100th percentile).
What to do: Upgrade VigorConnect beyond 1.6.0-B3 to the latest vendor release per DrayTek's instructions, or discontinue use of the product if mitigations are unavailable, as required by the CISA KEV listing. Until patched, restrict access to the VigorConnect web interface, including the DownloadFileServlet endpoint, to trusted management networks via firewall rules or VPN. Also check exposed instances for signs that sensitive files (e.g., password files or private keys) were retrieved, and rotate any credentials accessible to the host.
| DrayTek VigorConnect | 1.6.0-B3 (broader affected and fixed version ranges not specified in the available data) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A local file inclusion vulnerability exists in Draytek VigorConnect 1.6.0-B3 in the file download functionality of the DownloadFileServlet endpoint. An unauthenticated attacker could leverage this vulnerability to download arbitrary files from the underlying operating system with root privileges.
- Affected
- DrayTek VigorConnect
- Required action
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- draytek
- Products
- vigorconnect
- Weakness
- CWE-22
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N