Security
Loading…

CVE-2021-20124

UNKNOWNKnown Exploited
Description

Draytek VigorConnect contains a path traversal vulnerability in the file download functionality of the WebServlet endpoint. An unauthenticated attacker could leverage this vulnerability to download arbitrary files from the underlying operating system with root privileges.

Timeline
Published:September 3rd, 2024 12:00 AM
Last modified:September 3rd, 2024 12:00 AM
Added to KEV:September 3rd, 2024
CVSS Scoring

No CVSS v3 score available

Affected Software
From NVD CPE configuration data

Vendors

DrayTek

Products

VigorConnect
Weaknesses (CWE)
References & Reports
Advisories, patches, and third-party reports

No references available.

Source: CISA KEV + NVD · Data may lag official sources by up to one minute