CVE-2021-20124

A local file inclusion vulnerability exists in Draytek VigorConnect 1.6.0-B3 in the file download functionality of the WebServlet endpoint. An unauthenticated attacker could leverage this vulnerability to download arbitrary files from the underlying operating system with root privileges.

  • Published Oct 13, 2021
  • CVSS 7.5 high
  • 96.3% chance of exploitation in the next 30 days (EPSS)
  • In CISA's Known Exploited Vulnerabilities catalog
  • Public exploit code is available

Affected software

CVE-2021-20124 at the National Vulnerability Database