Impact
A directory traversal flaw in the getSyslogFile function of DrayTek VigorSwitch devices allows a remote attacker who can authenticate to the web management console to request arbitrary files on the device. The vulnerability is caused by insufficient validation of an option field, enabling a crafted request to include traversal sequences such as "../../". Successful exploitation could expose sensitive data, such as configuration files, passwords, or system logs, leading to a confidentiality breach and potentially facilitating further attacks against the network.
Affected Systems
DrayTek Corporation’s VigorSwitch line of switches, including models FX2120, G1280, G1282, G2100, G2121, G2280x, G2282x, G2540x, G2540xs, G2542x, P1280, P1281x, P1282, P2100, P2121, P2280x, P2282x, P2540x, P2540xs, P2542x, P2542xh, PQ2121x, PQ2200xb, PQ2300xb, PX2060, Q2121x, Q2200x, and Q2300x.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate to high severity that could be leveraged by a malicious actor with administrative access. EPSS data is not available, so the current probability of exploitation is unknown. The vulnerability is not yet listed in the CISA KEV catalogue, but its impact means that any device with a web interface exposed to untrusted networks should be remediated promptly. attackers must have valid administrative credentials; remote exploitation is possible over HTTP/HTTPS to the management interface.
OpenCVE Enrichment