CVE Vulnerabilities

CVE-2021-20127

Published: Oct 13, 2021 | Modified: Oct 19, 2021
CVSS 3.x
8.1
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
CVSS 2.x
8.5 HIGH
AV:N/AC:L/Au:S/C:N/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

An arbitrary file deletion vulnerability exists in the file delete functionality of the Html5Servlet endpoint of Draytek VigorConnect 1.6.0-B3. This allows an authenticated user to arbitrarily delete files in any location on the target operating system with root privileges.

Affected Software

Name Vendor Start Version End Version
Vigorconnect Draytek 1.6.0-beta3 (including) 1.6.0-beta3 (including)

References