Description


A local file inclusion vulnerability exists in Draytek VigorConnect 1.6.0-B3 in the file download functionality of the WebServlet endpoint. An unauthenticated attacker could leverage this vulnerability to download arbitrary files from the underlying operating system with root privileges.

Related CPE's


Weaknesses



CWE-22

134c704f-9b21-4f2e-91b3-4a467353bcc0

Secondary

CWE-22

CVSS impact metrics


CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

7.5 · High

Information


Source identifier

[email protected]

Vulnerability status

Analyzed

Published

2021-10-13T14:15:07.397Z

4 years ago

Last modified

2025-11-03T17:59:02.260Z

4 months ago