Skip to content
COOEY

EXPOSURES › CVE-2021-20124

CVE-2021-20124

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2024-09-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-20124 ↗
⌖ EXPLOITED IN THE WILD SHAME 65/100 exploited-in-wildsupply-chainunpatched

DrayTek's VigorConnect router allows unauthenticated attackers to download arbitrary OS files with root privileges via a path traversal flaw in the WebServlet endpoint.

This vulnerability enables an unauthenticated attacker to read sensitive system files, potentially exposing credentials or triggering further compromise. For DIB organizations, this represents a critical supply-chain risk where compromised hardware could be leveraged to breach internal networks, violating NIST 800-171 confidentiality requirements. Immediate firmware updates and network segmentation are required to mitigate exposure.

Shame score — A high-severity path traversal flaw in a widely deployed router product that allows unauthenticated access to root-level system files.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Draytek VigorConnect contains a path traversal vulnerability in the file download functionality of the WebServlet endpoint. An unauthenticated attacker could leverage this vulnerability to download arbitrary files from the underlying operating system with root privileges.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.