← Back to browse · API

CVE-2021-20124

Severity
HIGH
CVSS
7.5
EPSS
0.70659
Risk score
79.73
CISA KEV
Yes
PoC
No
Published
2024-09-03
Modified
2024-09-03
First seen
2026-08-07
Aliases
EUVD-2021-7581, GHSA-HJ9J-3XXG-6259
Products
DrayTek:VigorConnect, n/a:Draytek VigorConnect 1.6.0-B3
Sources
euvd EUVD-2021-7581
cisa.gov CVE-2021-20124

Description

Draytek VigorConnect contains a path traversal vulnerability in the file download functionality of the WebServlet endpoint. An unauthenticated attacker could leverage this vulnerability to download arbitrary files from the underlying operating system with root privileges.

References