CVE-2021-20124
Last modified
CVE-2021-20124 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. A local file inclusion vulnerability exists in Draytek VigorConnect 1.6.0-B3 in the file download functionality of the WebServlet endpoint. An unauthenticated attacker could leverage this vulnerability to download arbitrary files from the underlying operating system with root privileges.. CISA has confirmed active exploitation in the wild. EPSS estimates a 69.25% chance of exploitation in the next 30 days.
Description
A local file inclusion vulnerability exists in Draytek VigorConnect 1.6.0-B3 in the file download functionality of the WebServlet endpoint. An unauthenticated attacker could leverage this vulnerability to download arbitrary files from the underlying operating system with root privileges.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitation Status
This vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Federal agencies must remediate by .
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Draytek | Vigorconnect | 1.6.0 | Beta3 |
References
- https://www.tenable.com/security/research/tra-2021-42Exploit, Third Party Advisory
- https://www.tenable.com/security/research/tra-2021-42Exploit, Third Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-20124US Government Resource
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2021-20124?
How severe is CVE-2021-20124?
How do I fix CVE-2021-20124?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-20119The password change utility for the Arris SurfBoard SB8200 c…7.1
- CVE-2021-2012Vulnerability in the MySQL Server product of Oracle MySQL (c…4.9
- CVE-2021-20120The administration web interface for the Arris Surfboard SB8…8.8
- CVE-2021-20121The Telus Wi-Fi Hub (PRV65B444A-S-TS) with firmware version …4
- CVE-2021-20122The Telus Wi-Fi Hub (PRV65B444A-S-TS) with firmware version …7.2
- CVE-2021-20123A local file inclusion vulnerability exists in Draytek Vigor…7.5
- CVE-2021-20125An arbitrary file upload and directory traversal vulnerabili…9.8
- CVE-2021-20126Draytek VigorConnect 1.6.0-B3 lacks cross-site request forge…8.8
- CVE-2021-20127An arbitrary file deletion vulnerability exists in the file …8.1
- CVE-2021-20128The Profile Name field in the floor plan (Network Menu) page…5.4
- CVE-2021-20129An information disclosure vulnerability exists in Draytek Vi…7.5
- CVE-2021-2013Vulnerability in the Oracle BI Publisher product of Oracle F…7.6
Are you affected by CVE-2021-20124?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
