RaqibCTI
CVE

CVE-2021-20123

P2
Draytek VigorConnect Path Traversal Vulnerability
DrayTek · VigorConnect
Date added (CISA)
2024-09-03
Remediation due
2024-09-24
Known ransomware use
Not indicated
Remediation priority
P2past CISA due date

Description

Draytek VigorConnect contains a path traversal vulnerability in the DownloadFileServlet endpoint. An unauthenticated attacker could leverage this vulnerability to download arbitrary files from the underlying operating system with root privileges.

Source: NVD ↗ · CISA KEV Catalog ↗