OpsBuzz

Alert

Draytek VigorConnect Path Traversal Vulnerability

Draytek VigorConnect contains a path traversal vulnerability in the DownloadFileServlet endpoint. An unauthenticated attacker could leverage this vulnerabi

Security · HIGH
Source: CISA Known Exploited VulnerabilitiesMay 2, 2026, 4:51 PMSecurityhigh

Full content

Draytek VigorConnect contains a path traversal vulnerability in the DownloadFileServlet endpoint. An unauthenticated attacker could leverage this vulnerability to download arbitrary files from the underlying operating system with root privileges.

Vendor: DrayTek

Product: VigorConnect

Due date: 2024-09-24

Known ransomware use: Unknown

Why it matters

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Related alerts