ZeroHour

CVE-2021-20124

KEV PoC moderate

Unauthenticated Path Traversal File Download in DrayTek VigorConnect

CISA: Draytek VigorConnect Path Traversal Vulnerability

CVSS 3.1
7.5 high
EPSS
96%p100
Published
()
KEV added
AI analysis

CVE-2021-20124 is a path traversal (local file inclusion, CWE-22) flaw in the file download functionality of the WebServlet endpoint in DrayTek VigorConnect 1.6.0-B3, the vendor's on-premises centralized management software for Vigor networking equipment. Because the affected endpoint requires no authentication, any attacker who can reach the VigorConnect web interface over a network can send crafted requests that traverse outside the intended download directory. The VigorConnect service runs with root privileges on the underlying operating system, so an attacker can download arbitrary files with root-level access, potentially exposing credentials, configuration data, and other sensitive information on the management host. Any organization running DrayTek VigorConnect is affected, with the flaw confirmed in version 1.6.0-B3. The bug was publicly documented by Tenable (TRA-2021-42) in 2021 and was added to CISA's Known Exploited Vulnerabilities catalog on 2024-09-03 amid reports of active exploitation of DrayTek devices.

What to do: Upgrade DrayTek VigorConnect to a fixed release newer than 1.6.0-B3 per DrayTek's security guidance; if patching is delayed, restrict the VigorConnect web interface (WebServlet endpoint) to trusted management networks only. Because the flaw is on CISA's KEV catalog (added 2024-09-03) with active exploitation reported, review firewall and web-server logs for unauthenticated file-download requests against WebServlet, and rotate any credentials, keys, or configuration secrets stored on the management host that could have been exfiltrated. Organizations unable to obtain mitigations should consider discontinuing use of the product per CISA's required action.

Affected
DrayTek VigorConnect1.6.0-B3 (version confirmed vulnerable in the advisory; no other version ranges specified in available data)
Estimated exposure
moderatelikely on the order of thousands of on-premises VigorConnect management-server deployments worldwide (estimate; no public install counts provided) — VigorConnect is DrayTek's free on-prem central management platform, installed one server per organization, so the affected base is only a fraction of DrayTek's large SMB router installed base; no public active-install or internet-scan…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A local file inclusion vulnerability exists in Draytek VigorConnect 1.6.0-B3 in the file download functionality of the WebServlet endpoint. An unauthenticated attacker could leverage this vulnerability to download arbitrary files from the underlying operating system with root privileges.

CISA Known Exploited Vulnerability
Affected
DrayTek VigorConnect
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
draytek
Products
vigorconnect
Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news