Vulnerability record · CVE-2021-20124 · published 13 October 2021
CVE-2021-20124: Draytek VigorConnect path traversal allows unauthenticated file download
Draytek · Vigorconnect
Draytek VigorConnect 1.6.0-B3 contains a path traversal (local file inclusion) flaw in the file download functionality of the WebServlet endpoint. An unauthenticated attacker can request arbitrary files from the underlying operating system, and the files are returned with root privileges. Because no credentials or user interaction are required and the service is network reachable, it is a serious exposure for any internet-facing instance.
Description
A local file inclusion vulnerability exists in Draytek VigorConnect 1.6.0-B3 in the file download functionality of the WebServlet endpoint. An unauthenticated attacker could leverage this vulnerability to download arbitrary files from the underlying operating system with root privileges.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
critical priorityUnauthenticated network-reachable arbitrary file read as root, listed in CISA KEV with a public exploit and near-maximum EPSS score.
What it is
Draytek VigorConnect 1.6.0-B3 contains a path traversal (local file inclusion) flaw in the file download functionality of the WebServlet endpoint. An unauthenticated attacker can request arbitrary files from the underlying operating system, and the files are returned with root privileges. Because no credentials or user interaction are required and the service is network reachable, it is a serious exposure for any internet-facing instance.
Impact
An attacker gains read access to arbitrary files on the host, including configuration and credential material, with the reads performed as root. This can expose secrets that enable further compromise of the appliance or connected network.
Attack surface
Reached over the network via the WebServlet file download endpoint; the CVSS vector shows AV:N/PR:N/UI:N, so no authentication and no user interaction are needed. Any host that can reach the VigorConnect web interface can attempt the request.
Exploitation
The vulnerability is listed in CISA KEV (added 2024-09-03, due 2024-09-24) and has a public exploit reference from Tenable, indicating active exploitation. EPSS is 0.96308 (99.878th percentile), consistent with high likelihood of exploitation attempts.
What to do
- Apply the vendor fix for VigorConnect or upgrade to a non-vulnerable release; if no fix is available, discontinue use of the product as CISA directs.
- Remove VigorConnect web interfaces from direct internet exposure and restrict access to trusted management networks.
- If the product cannot be patched or isolated, take it offline until a supported remediation exists.
- Rotate any credentials, keys or certificates that may have been stored on or reachable from the affected host.
- Monitor vendor advisories for updated guidance and re-check exposure after any change.
Detection
- Review web server or proxy logs for requests to the WebServlet file download endpoint containing path traversal sequences such as ../ or encoded variants.
- Alert on file download requests returning unusually large responses or files outside expected web content paths.
- Hunt for access to sensitive OS files (for example /etc/passwd or configuration files) through the VigorConnect service.
- Correlate VigorConnect access logs with outbound connections or follow-on authentication attempts from the same source.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2021-20124 to the Known Exploited Vulnerabilities catalog on 3 September 2024 as "Draytek VigorConnect Path Traversal Vulnerability ". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 24 September 2024.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.tenable.com/security/research/tra-2021-42 | ExploitThird Party Advisory |
| https://www.tenable.com/security/research/tra-2021-42 | ExploitThird Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-20124 | US Government Resource |
Track CVE-2021-20124 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-20124), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.