← Vulnerability feed

Vulnerability record · CVE-2021-20123 · published 13 October 2021

CVE-2021-20123: Draytek VigorConnect path traversal in DownloadFileServlet

Draytek · Vigorconnect

Draytek VigorConnect 1.6.0-B3 contains a path traversal (local file inclusion) flaw in the file download functionality of the DownloadFileServlet endpoint. An unauthenticated attacker can download arbitrary files from the underlying operating system, and the files are read with root privileges, so sensitive configuration and credential material is exposed. It matters because the flaw is remotely reachable without credentials and is listed in CISA's Known Exploited Vulnerabilities catalog.

7.5 CVSS 3.1 High CISA KEV since 3 Sep 2024 EPSS 90% · top 0.2% CWE-22 · Path traversal
7.5CVSS 3.1 base score, v2 7.8
90%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
3References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

A local file inclusion vulnerability exists in Draytek VigorConnect 1.6.0-B3 in the file download functionality of the DownloadFileServlet endpoint. An unauthenticated attacker could leverage this vulnerability to download arbitrary files from the underlying operating system with root privileges.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityIt is an unauthenticated, remotely reachable arbitrary file read with root privileges that CISA lists as exploited in the wild and that carries a very high EPSS score.

What it is

Draytek VigorConnect 1.6.0-B3 contains a path traversal (local file inclusion) flaw in the file download functionality of the DownloadFileServlet endpoint. An unauthenticated attacker can download arbitrary files from the underlying operating system, and the files are read with root privileges, so sensitive configuration and credential material is exposed. It matters because the flaw is remotely reachable without credentials and is listed in CISA's Known Exploited Vulnerabilities catalog.

Impact

An attacker gains read access to arbitrary files on the host with root privileges, exposing configuration, credential and system files. There is no integrity or availability impact per the CVSS vector; the loss is confidentiality.

Attack surface

Reached over the network through the DownloadFileServlet file download endpoint, per the CVSS vector AV:N/AC:L/PR:N/UI:N. No authentication and no user interaction are required.

Exploitation

CISA added it to the Known Exploited Vulnerabilities catalog on 2024-09-03 with a remediation due date of 2024-09-24, indicating exploitation in the wild. EPSS is very high (0.90234 probability, 99.791 percentile) and a public exploit reference exists from Tenable; no ransomware campaign use is documented.

What to do

  • Apply the vendor's patch or mitigation instructions for VigorConnect; if no fix is available, discontinue use of the product as CISA directs.
  • Restrict network access to the VigorConnect management/download interface to trusted administrative networks only.
  • Run the service with least privilege rather than root so file reads cannot reach the whole filesystem.
  • Rotate any credentials or secrets stored on the appliance that may have been exposed.
  • Monitor CISA KEV guidance and vendor advisories for updated remediation.

Detection

  • Review web server or application logs for requests to DownloadFileServlet containing path traversal sequences such as ../ or encoded variants.
  • Alert on downloads of sensitive paths (for example /etc/passwd, configuration or key files) from the VigorConnect host.
  • Baseline normal DownloadFileServlet request patterns and flag anomalous or high-volume file retrieval from unexpected source IPs.
  • Hunt for outbound connections or file access consistent with post-exploitation credential use from the VigorConnect host.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2021-20123 to the Known Exploited Vulnerabilities catalog on 3 September 2024 as "Draytek VigorConnect Path Traversal Vulnerability ". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 24 September 2024.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-20123 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2021-20124Draytek VigorConnect path traversal allows unauthenticated file downloadDraytek VigorConnect 1.6.0-B3 contains a path traversal (local file inclusion) flaw in the file download functionality of the WebServlet endpoint. An…KEVEPSS 96%analysed9.8CVE-2021-20125Draytek vigorconnect path traversal vulnerabilityAn arbitrary file upload and directory traversal vulnerability exists in the file upload functionality of DownloadFileServlet in Draytek VigorConnect…EPSS 3.9%8.8CVE-2021-20126Draytek vigorconnect cross-site request forgery vulnerabilityDraytek VigorConnect 1.6.0-B3 lacks cross-site request forgery protections and does not sufficiently verify whether a well-formed, valid, consistent …EPSS 0.63%8.1CVE-2021-20127Draytek vigorconnect vulnerabilityAn arbitrary file deletion vulnerability exists in the file delete functionality of the Html5Servlet endpoint of Draytek VigorConnect 1.6.0-B3. This …EPSS 1.1%7.5CVE-2021-20129Draytek vigorconnect sensitive information in log file vulnerabilityAn information disclosure vulnerability exists in Draytek VigorConnect 1.6.0-B3, allowing an unauthenticated attacker to export system logs.EPSS 1.7%5.4CVE-2021-20128Draytek vigorconnect cross-site scripting vulnerabilityThe Profile Name field in the floor plan (Network Menu) page in Draytek VigorConnect 1.6.0-B3 was found to be vulnerable to stored XSS, as user input…EPSS 0.57%9.8CVE-2026-93616Checkpoint multi-domain security management path traversal vulnerabilityA directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Managem…KEVEPSS 20%10.0CVE-2026-85706GitLab CE/EE repository commits API path traversal allows unauthenticated file readGitLab CE/EE contains improper path confinement and missing authentication enforcement in the repository commits API, allowing an unauthenticated use…KEVEPSS 91%analysed

Source: NIST National Vulnerability Database (record CVE-2021-20123), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.