EXPOSURES › CVE-2021-20123
CVE-2021-20123
HIGH ⌖ ON CISA KEV · EXPLOITEDDrayTek's VigorConnect router allows unauthenticated attackers to download arbitrary OS files with root privileges via a path traversal flaw in the DownloadFileServlet endpoint.
This unpatched vulnerability enables attackers to exfiltrate sensitive system files from the underlying OS, posing a severe supply-chain and data-breach risk for DIB organizations relying on DrayTek hardware. Because the flaw allows arbitrary file access with root privileges, it is an RCE equivalent that could facilitate ransomware entry or lateral movement. DIB orgs must immediately audit all DrayTek devices for this CVE and apply vendor patches or replace compromised hardware to avoid FCA settlement exposure.
Shame score — A high-severity, actively exploited path traversal flaw in a widely deployed router product that allows unauthenticated root-level file access represents a critical negligence in vendor security hygiene.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Draytek VigorConnect contains a path traversal vulnerability in the DownloadFileServlet endpoint. An unauthenticated attacker could leverage this vulnerability to download arbitrary files from the underlying operating system with root privileges.