Beveiligingsadvies

CVE-2021-20124

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2021-10-13 15:48:03
Laatst bijgewerkt 2025-10-21 23:25:28
Toegewezen door tenable
CVSS-score 7.5
Status PUBLISHED

Beschrijving

A local file inclusion vulnerability exists in Draytek VigorConnect 1.6.0-B3 in the file download functionality of the WebServlet endpoint. An unauthenticated attacker could leverage this vulnerability to download arbitrary files from the underlying operating system with root privileges.