Skip to content
COOEY

FAIL › dossier

VigorConnect

PRODUCT

· dossier confidence 50%

VigorConnect routers suffer from critical unauthenticated remote code execution vulnerabilities via path traversal flaws, allowing attackers to download arbitrary OS files with root privileges.

PROFILE
Categorynetworking hardwareWhat they doVigorConnect is a router product manufactured by DrayTek.
SECURITY POSTURE

Demonstrates a pattern of critical remote code execution vulnerabilities in its VigorConnect router, with unauthenticated path traversal flaws allowing arbitrary OS file downloads with root privileges.

Notable failures
  • CVE-2021-20123: unauthenticated RCE via path traversal in DownloadFileServlet
  • CVE-2021-20124: unauthenticated RCE via path traversal in WebServlet
Patterns: repeated unpatched edge-device RCEs
FAILURE HISTORY · 2
DATEEVENTSEVSUMMARY
2024-09-03 CVE-2021-20123 high DrayTek's VigorConnect router allows unauthenticated attackers to download arbitrary OS files with root privileges via a path traversal flaw in the DownloadFileServlet endpoint.
2024-09-03 CVE-2021-20124 high DrayTek's VigorConnect router allows unauthenticated attackers to download arbitrary OS files with root privileges via a path traversal flaw in the WebServlet endpoint.
Open questions: DrayTek's founding year and headquarters location
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-28 04:07:25.725197+00:00