CVE-2021-20127

An arbitrary file deletion vulnerability exists in the file delete functionality of the Html5Servlet endpoint of Draytek VigorConnect 1.6.0-B3. This allows an authenticated user to arbitrarily delete files in any location on the target operating system with root privileges.
References
Link Resource
https://www.tenable.com/security/research/tra-2021-42 Exploit Third Party Advisory
Configurations

Configuration 1

cpe:2.3:a:draytek:vigorconnect:1.6.0:beta3:*:*:*:*:*:*

Information

Published : 2021-10-13 04:15

Updated : 2021-10-19 06:10


NVD link : CVE-2021-20127

Mitre link : CVE-2021-20127

Products Affected
No products.