CVE-2021-20124
KEV PoC moderateUnauthenticated Path Traversal File Download in DrayTek VigorConnect
CISA: Draytek VigorConnect Path Traversal Vulnerability
CVE-2021-20124 is a path traversal (local file inclusion, CWE-22) flaw in the file download functionality of the WebServlet endpoint in DrayTek VigorConnect 1.6.0-B3, the vendor's on-premises centralized management software for Vigor networking equipment. Because the affected endpoint requires no authentication, any attacker who can reach the VigorConnect web interface over a network can send crafted requests that traverse outside the intended download directory. The VigorConnect service runs with root privileges on the underlying operating system, so an attacker can download arbitrary files with root-level access, potentially exposing credentials, configuration data, and other sensitive information on the management host. Any organization running DrayTek VigorConnect is affected, with the flaw confirmed in version 1.6.0-B3. The bug was publicly documented by Tenable (TRA-2021-42) in 2021 and was added to CISA's Known Exploited Vulnerabilities catalog on 2024-09-03 amid reports of active exploitation of DrayTek devices.
What to do: Upgrade DrayTek VigorConnect to a fixed release newer than 1.6.0-B3 per DrayTek's security guidance; if patching is delayed, restrict the VigorConnect web interface (WebServlet endpoint) to trusted management networks only. Because the flaw is on CISA's KEV catalog (added 2024-09-03) with active exploitation reported, review firewall and web-server logs for unauthenticated file-download requests against WebServlet, and rotate any credentials, keys, or configuration secrets stored on the management host that could have been exfiltrated. Organizations unable to obtain mitigations should consider discontinuing use of the product per CISA's required action.
| DrayTek VigorConnect | 1.6.0-B3 (version confirmed vulnerable in the advisory; no other version ranges specified in available data) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A local file inclusion vulnerability exists in Draytek VigorConnect 1.6.0-B3 in the file download functionality of the WebServlet endpoint. An unauthenticated attacker could leverage this vulnerability to download arbitrary files from the underlying operating system with root privileges.
- Affected
- DrayTek VigorConnect
- Required action
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- draytek
- Products
- vigorconnect
- Weakness
- CWE-22
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N