← Back to browse · API

CVE-2021-20123

Severity
HIGH
CVSS
7.5
EPSS
0.75433
Risk score
81.4
CISA KEV
Yes
PoC
No
Published
2024-09-03
Modified
2024-09-03
First seen
2026-08-07
Aliases
EUVD-2021-7580, GHSA-GC9M-33CP-RMPJ
Products
DrayTek:VigorConnect, n/a:Draytek VigorConnect 1.6.0-B3
Sources
euvd EUVD-2021-7580
cisa.gov CVE-2021-20123

Description

Draytek VigorConnect contains a path traversal vulnerability in the DownloadFileServlet endpoint. An unauthenticated attacker could leverage this vulnerability to download arbitrary files from the underlying operating system with root privileges.

References