S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-20124 Scanner

CVE-2021-20124 scanner - Local File Inclusion vulnerability in Draytek VigorConnect

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.8k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2021-20124
7.5
CVSShigh
Exploitable remotely over the internet · no authentication required.

A local file inclusion vulnerability exists in Draytek VigorConnect 1.6.0-B3 in the file download functionality of the WebServlet endpoint. An unauthenticated attacker could leverage this vulnerability to download arbitrary files from the underlying operating system with root privileges.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Draytek VigorConnectby n/a
1.6.0-B3
vigorconnectby draytek
1.6.0
Updated Aug 21, 2026View on NVD →
Detail

Draytek VigorConnect is a network management software that is primarily used by small and medium-sized enterprises. It allows network administrators to manage their routers, switches, and other network devices from a single, centralized location. The software provides a range of features, including network monitoring, device configuration, and firmware updates. It is designed to make network management simpler and more efficient.

CVE-2021-20124 is a critical vulnerability that was detected in Draytek VigorConnect 1.6.0-B3. The vulnerability exists in the file download functionality of the WebServlet endpoint, allowing an unauthenticated attacker to download any file from the underlying operating system with root privileges. This means that attackers could gain complete control over the network infrastructure of an organization, potentially leading to data theft, network disruption, or even ransomware attacks.

If this vulnerability is exploited, it can have serious consequences for affected organizations. Hackers could gain access to sensitive data, install backdoors, or carry out other malicious activities that could disrupt the network and cause severe damage to an organization's reputation. Moreover, the vulnerability can be exploited remotely, which means that attackers could target multiple organizations at once, increasing the potential for widespread damage.

By using the pro features of the s4e.io platform, readers of this article can easily and quickly learn about vulnerabilities in their digital assets. The platform provides real-time alerts and notifications for new vulnerabilities, as well as detailed information on how to patch and protect against them. With s4e.io, organizations can stay one step ahead of cyber threats and keep their networks safe and secure.

 

REFERENCES

Solution Advice

There are several precautions that organizations can take to protect against this vulnerability. Some of these include:

  • Applying the latest security patches and updates provided by Draytek.
  • Disabling the WebServlet endpoint if it is not being used.
  • Restricting access to the VigorConnect software to trusted users and networks.
  • Enabling two-factor authentication to prevent unauthorized access to the software.
  • Monitoring network traffic for unusual activity that may indicate an attack.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.