A AegiFlow
UNKNOWNKNOWN EXPLOITED

CVE-2021-20123

Draytek VigorConnect Path Traversal Vulnerability

Published
2024-09-03
Modified
2026-07-31
Sources
cisa-kev

Summary

Draytek VigorConnect contains a path traversal vulnerability in the DownloadFileServlet endpoint. An unauthenticated attacker could leverage this vulnerability to download arbitrary files from the underlying operating system with root privileges.

References

Includes data from the CISA Known Exploited Vulnerabilities catalog.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.