LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2021-20123: Draytek VigorConnect Path Traversal Vulnerability

RBRecent Breaches Vulnerability Intelligence·Sep 3, 2024
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Sep 24, 2024
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2021-20123 to its Known Exploited Vulnerabilities catalog on Sep 3, 2024, with a federal patch deadline of Sep 24, 2024 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Draytek VigorConnect contains a path traversal vulnerability in the DownloadFileServlet endpoint. An unauthenticated attacker could leverage this vulnerability to download arbitrary files from the…

CVE-2021-20123 is a path traversal vulnerability in DrayTek VigorConnect that allows an unauthenticated attacker to download arbitrary files from the underlying operating system with root privileges via the DownloadFileServlet endpoint. This matters because VigorConnect is often used to manage network devices and infrastructure; successful abuse can expose sensitive configuration files, credentials, or other system data without any authentication barrier, increasing the risk of further compromise of the management platform and connected assets.

Defenders should treat this as a high-priority issue for any deployment of the product until the vendor's recommended actions are confirmed and applied. Public detail is limited to the facts above; always verify exact scope against the vendor advisory.

How it works

The flaw belongs to the path traversal class (CWE-22). In this weakness, an application fails to properly sanitize user-supplied input that is used to construct file paths. An attacker can insert directory traversal sequences to escape the intended directory and reach files elsewhere on the filesystem.

According to the available summary, the vulnerable component is the DownloadFileServlet endpoint in DrayTek VigorConnect. An unauthenticated remote attacker can leverage the path traversal to request and retrieve arbitrary files from the operating system, executing the read with root privileges. No further exploit mechanics are provided in the public record; specifics of request format or payload construction must be confirmed against the vendor advisory rather than assumed.

Am I affected? How to find it in your systems

DrayTek VigorConnect is management software typically deployed on servers or appliances used to administer DrayTek networking equipment. It may appear in enterprise or service-provider environments that centralize configuration and monitoring of routers, firewalls, or VPN devices.

How to remediate

Patch first. Apply the vendor update or mitigations named in the official advisory for DrayTek VigorConnect. CISA directs organizations to apply mitigations per vendor instructions or to discontinue use of the product if mitigations are unavailable.

Confirm all version and configuration guidance directly from the vendor advisory before declaring systems remediated.

If you can't patch immediately

Implement compensating controls to reduce exposure until the vendor update can be applied.

If your data may have been exposed

Actively exploited vulnerabilities of this class can lead to data breaches when attackers retrieve sensitive files. Known ransomware use of this CVE is not documented. If you suspect exposure, preserve logs, isolate affected systems, and follow your incident response process. You can also run a free exposure scan of your email address to check whether it appears in known breach data sets as one additional indicator of compromise.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedDrayTek · VigorConnect
WeaknessCWE-22
Added to CISA KEVSep 3, 2024
Federal patch deadlineSep 24, 2024
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities