CVE-2021-20124 is a critical local file inclusion vulnerability in Draytek VigorConnect 1.6.0-B3, allowing unauthenticated attackers to download arbitrary files with root privileges. With a CVSS score of 7.5 (HIGH) and an EPSS score indicating high exploitability, this vulnerability poses a significant risk. It is actively exploited in the wild, as confirmed by its presence in the CISA KEV catalog and extensive media coverage, despite the absence of public Metasploit or ExploitDB modules. The high community discussion and FAUCET Risk Score of 100/100 further underscore its severity and active threat landscape.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.6.0CPE matchmatch criteria | cpe:2.3:a:draytek:vigorconnect:1.6.0:beta3:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Multiple Vulnerabilities in Draytek VigorConnect 1.60.0-B3
Oct 12, 2021Multiple Vulnerabilities in Draytek VigorConnect 1.60.0-B3
Oct 12, 2021Multiple Vulnerabilities in Draytek VigorConnect 1.60.0-B3
Oct 12, 2021Multiple Vulnerabilities in Draytek VigorConnect 1.60.0-B3
Oct 12, 2021Multiple Vulnerabilities in Draytek VigorConnect 1.60.0-B3
Oct 12, 2021