An arbitrary file deletion vulnerability exists in the file delete functionality of the Html5Servlet endpoint of Draytek VigorConnect 1.6.0-B3. This allows an authenticated user to arbitrarily delete files in any location on the target operating system with root privileges.
Advisories
Source ID Title
EUVD EUVD EUVD-2021-7584 An arbitrary file deletion vulnerability exists in the file delete functionality of the Html5Servlet endpoint of Draytek VigorConnect 1.6.0-B3. This allows an authenticated user to arbitrarily delete files in any location on the target operating system with root privileges.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: tenable

Published:

Updated: 2024-08-03T17:30:07.367Z

Reserved: 2020-12-17T00:00:00

Link: CVE-2021-20127

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-10-13T16:15:07.517

Modified: 2024-11-21T05:45:58.587

Link: CVE-2021-20127

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.