Vulnerability record · CVE-2021-20123 · published 13 October 2021
CVE-2021-20123: Draytek VigorConnect path traversal in DownloadFileServlet
Draytek · Vigorconnect
Draytek VigorConnect 1.6.0-B3 contains a path traversal (local file inclusion) flaw in the file download functionality of the DownloadFileServlet endpoint. An unauthenticated attacker can download arbitrary files from the underlying operating system, and the files are read with root privileges, so sensitive configuration and credential material is exposed. It matters because the flaw is remotely reachable without credentials and is listed in CISA's Known Exploited Vulnerabilities catalog.
Description
A local file inclusion vulnerability exists in Draytek VigorConnect 1.6.0-B3 in the file download functionality of the DownloadFileServlet endpoint. An unauthenticated attacker could leverage this vulnerability to download arbitrary files from the underlying operating system with root privileges.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
critical priorityIt is an unauthenticated, remotely reachable arbitrary file read with root privileges that CISA lists as exploited in the wild and that carries a very high EPSS score.
What it is
Draytek VigorConnect 1.6.0-B3 contains a path traversal (local file inclusion) flaw in the file download functionality of the DownloadFileServlet endpoint. An unauthenticated attacker can download arbitrary files from the underlying operating system, and the files are read with root privileges, so sensitive configuration and credential material is exposed. It matters because the flaw is remotely reachable without credentials and is listed in CISA's Known Exploited Vulnerabilities catalog.
Impact
An attacker gains read access to arbitrary files on the host with root privileges, exposing configuration, credential and system files. There is no integrity or availability impact per the CVSS vector; the loss is confidentiality.
Attack surface
Reached over the network through the DownloadFileServlet file download endpoint, per the CVSS vector AV:N/AC:L/PR:N/UI:N. No authentication and no user interaction are required.
Exploitation
CISA added it to the Known Exploited Vulnerabilities catalog on 2024-09-03 with a remediation due date of 2024-09-24, indicating exploitation in the wild. EPSS is very high (0.90234 probability, 99.791 percentile) and a public exploit reference exists from Tenable; no ransomware campaign use is documented.
What to do
- Apply the vendor's patch or mitigation instructions for VigorConnect; if no fix is available, discontinue use of the product as CISA directs.
- Restrict network access to the VigorConnect management/download interface to trusted administrative networks only.
- Run the service with least privilege rather than root so file reads cannot reach the whole filesystem.
- Rotate any credentials or secrets stored on the appliance that may have been exposed.
- Monitor CISA KEV guidance and vendor advisories for updated remediation.
Detection
- Review web server or application logs for requests to DownloadFileServlet containing path traversal sequences such as ../ or encoded variants.
- Alert on downloads of sensitive paths (for example /etc/passwd, configuration or key files) from the VigorConnect host.
- Baseline normal DownloadFileServlet request patterns and flag anomalous or high-volume file retrieval from unexpected source IPs.
- Hunt for outbound connections or file access consistent with post-exploitation credential use from the VigorConnect host.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2021-20123 to the Known Exploited Vulnerabilities catalog on 3 September 2024 as "Draytek VigorConnect Path Traversal Vulnerability ". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 24 September 2024.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.tenable.com/security/research/tra-2021-42 | ExploitThird Party Advisory |
| https://www.tenable.com/security/research/tra-2021-42 | ExploitThird Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-20123 | US Government Resource |
Track CVE-2021-20123 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-20123), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.