Aller au contenu

Fiche vulnérabilité

CVE-2021-20123 : faille exploitée draytek vigorconnect (CVSS 7.5)

Description

A local file inclusion vulnerability exists in Draytek VigorConnect 1.6.0-B3 in the file download functionality of the DownloadFileServlet endpoint. An unauthenticated attacker could leverage this vulnerability to download arbitrary files from the underlying operating system with root privileges.

En bref

Sévérité
Élevée (CVSS 7.5)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitation active
Oui, inscrite au catalogue CISA KEV
Publication
13 oct. 2021
Dernière mise à jour
17 juin 2026

Produits concernés

  • draytek vigorconnect

Correctif et mesures

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Références

Rechercher une autre vulnérabilité dans la base CVE