A AegiFlow
UNKNOWNKNOWN EXPLOITED

CVE-2021-20124

Draytek VigorConnect Path Traversal Vulnerability

Published
2024-09-03
Modified
2026-07-31
Sources
cisa-kev

Summary

Draytek VigorConnect contains a path traversal vulnerability in the file download functionality of the WebServlet endpoint. An unauthenticated attacker could leverage this vulnerability to download arbitrary files from the underlying operating system with root privileges.

References

Includes data from the CISA Known Exploited Vulnerabilities catalog.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.