Skip to content
COOEY

EXPOSURES › CVE-2021-20123

CVE-2021-20123

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2024-09-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-20123 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 exploited-in-wildunpatchedsupply-chaindata-breachransomware

DrayTek's VigorConnect router allows unauthenticated attackers to download arbitrary OS files with root privileges via a path traversal flaw in the DownloadFileServlet endpoint.

This unpatched vulnerability enables attackers to exfiltrate sensitive system files from the underlying OS, posing a severe supply-chain and data-breach risk for DIB organizations relying on DrayTek hardware. Because the flaw allows arbitrary file access with root privileges, it is an RCE equivalent that could facilitate ransomware entry or lateral movement. DIB orgs must immediately audit all DrayTek devices for this CVE and apply vendor patches or replace compromised hardware to avoid FCA settlement exposure.

Shame score — A high-severity, actively exploited path traversal flaw in a widely deployed router product that allows unauthenticated root-level file access represents a critical negligence in vendor security hygiene.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Draytek VigorConnect contains a path traversal vulnerability in the DownloadFileServlet endpoint. An unauthenticated attacker could leverage this vulnerability to download arbitrary files from the underlying operating system with root privileges.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.