CVE-2021-20124

Publication date

2021-10-13 15:48:03

Family

tenable

State

PUBLISHED

Description

A local file inclusion vulnerability exists in Draytek VigorConnect 1.6.0-B3 in the file download functionality of the WebServlet endpoint. An unauthenticated attacker could leverage this vulnerability to download arbitrary files from the underlying operating system with root privileges.