EUVD-2021-7580
A local file inclusion vulnerability exists in Draytek VigorConnect 1.6.0-B3 in the file download functionality of the DownloadFileServlet endpoint. An unauthenticated attacker could leverage this vulnerability to download arbitrary files from the underlying operating system with root privileges.
- EUVD state
- Present in the current official mapping
- Known exploitation
- Recorded by ENISA since 3 Sept 2024. Evidence sources: cisa_kev.
- ENISA score
- 7.5 · CVSS 3.1
- Advisory evidence
- No linked advisory details stored yet
