Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2021-20123

94
FAUCET Score

CVE-2021-20123 is a critical local file inclusion vulnerability affecting Draytek VigorConnect 1.6.0-B3, specifically within the DownloadFileServlet endpoint. An unauthenticated attacker can exploit this to download arbitrary files from the underlying operating system with root privileges. This vulnerability carries a high CVSS score of 7.5, indicating a network-based attack with low complexity and high confidentiality impact. It is actively exploited, listed in CISA's KEV catalog, and has garnered significant community discussion and media coverage, including reports of its use in widespread DrayTek router reboots.

Impacted Technologies

VendorProductVersion(s)CPE
1.6.0CPE matchmatch criteria
cpe:2.3:a:draytek:vigorconnect:1.6.0:beta3:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
74.28%
Probability of exploitation in next 30 days
EPSS Percentile
99.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
Added to KEV · Sep 3, 2024
Nuclei: CVE-2021-20123 · May 13, 2022
This CVE's current EPSS score of 0.7428 is in the 99th percentile among its peer group of 51,485 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (11)

asteriskvendor investigatingvia llm_extracted
capnprotovendor investigatingvia llm_extracted
View patch
ciscovendor investigatingvia llm_extracted
View patch
hedgedocvendor investigatingvia llm_extracted
View patch
hpvendor investigatingvia llm_extracted
View patch
jenkinsvendor investigatingvia llm_extracted
View patch
lycheeorgvendor investigatingvia llm_extracted
View patch
miniovendor investigatingvia llm_extracted
opensshvendor investigatingvia llm_extracted
railsvendor investigatingvia llm_extracted
yokogawavendor investigatingvia llm_extracted
View patch

Vendor Advisories (12)

yokogawallm-yokogawa-adbfe8f9cef62bf7

VigorConnect software security Vulnerability (CVE-2021-20123 - CVE-2021-20129)

Oct 15, 2021
lycheeorgllm-lycheeorg-8c187fba73669569

VigorConnect software security Vulnerability (CVE-2021-20123 - CVE-2021-20129)

Oct 15, 2021
jenkinsllm-jenkins-2072d5252b381408

VigorConnect software security Vulnerability (CVE-2021-20123 - CVE-2021-20129)

Oct 15, 2021
hpllm-hp-29982f726cbc9186

VigorConnect software security Vulnerability (CVE-2021-20123 - CVE-2021-20129)

Oct 15, 2021
hedgedocllm-hedgedoc-19fe20ccc9d6a82b

VigorConnect software security Vulnerability (CVE-2021-20123 - CVE-2021-20129)

Oct 15, 2021
capnprotollm-capnproto-78f32749c0394ad6

VigorConnect software security Vulnerability (CVE-2021-20123 - CVE-2021-20129)

Oct 15, 2021
ciscollm-cisco-b505a5fce60efe3d

VigorConnect software security Vulnerability (CVE-2021-20123 - CVE-2021-20129)

Oct 15, 2021
railsllm-rails-3ee2d605d8d3d4b4CRITICAL

Multiple Vulnerabilities in Draytek VigorConnect 1.60.0-B3

Oct 12, 2021
opensshllm-openssh-d6a63d7518184d6cCRITICAL

Multiple Vulnerabilities in Draytek VigorConnect 1.60.0-B3

Oct 12, 2021
miniollm-minio-82f06249fd1b229cCRITICAL

Multiple Vulnerabilities in Draytek VigorConnect 1.60.0-B3

Oct 12, 2021
ciscollm-cisco-e2b320a468b9b6bcCRITICAL

Multiple Vulnerabilities in Draytek VigorConnect 1.60.0-B3

Oct 12, 2021
asteriskllm-asterisk-ebe75604b0499798CRITICAL

Multiple Vulnerabilities in Draytek VigorConnect 1.60.0-B3

Oct 12, 2021

References

cisa.gov / known-exploited-vulnerabilities-catalog
US Government Resource
tenable.com / security/research/tra-2021-42
ExploitThird Party Advisory