EXPOSURES › CVE-2021-20124
CVE-2021-20124
HIGH ⌖ ON CISA KEV · EXPLOITEDDrayTek's VigorConnect router allows unauthenticated attackers to download arbitrary OS files with root privileges via a path traversal flaw in the WebServlet endpoint.
This vulnerability enables an unauthenticated attacker to read sensitive system files, potentially exposing credentials or triggering further compromise. For DIB organizations, this represents a critical supply-chain risk where compromised hardware could be leveraged to breach internal networks, violating NIST 800-171 confidentiality requirements. Immediate firmware updates and network segmentation are required to mitigate exposure.
Shame score — A high-severity path traversal flaw in a widely deployed router product that allows unauthenticated access to root-level system files.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Draytek VigorConnect contains a path traversal vulnerability in the file download functionality of the WebServlet endpoint. An unauthenticated attacker could leverage this vulnerability to download arbitrary files from the underlying operating system with root privileges.