Skip to content

Latest commit

 

History

History
17 lines (11 loc) · 801 Bytes

CVE-2021-20123.md

File metadata and controls

17 lines (11 loc) · 801 Bytes

Description

A local file inclusion vulnerability exists in Draytek VigorConnect 1.6.0-B3 in the file download functionality of the DownloadFileServlet endpoint. An unauthenticated attacker could leverage this vulnerability to download arbitrary files from the underlying operating system with root privileges.

POC

Reference

Github

No PoCs found on GitHub currently.