漏洞描述 Draytek VigorConnect1.6.0-B3容易受到WebServlet端点的文件下载功能中包含的本地文件的影响。未经身份验证的攻击者可以利用此漏洞以root权限从底层操作系统下载任意文件
相关漏洞推荐 CVE-2020-15415: DrayTek Vigor - Command Injection POC 2025-08-01 | DrayTek Vigor DrayTek Vigor devices contain a command injection vulnerability in the cvmcfgupload functionality. T... CVE-2021-20123: Draytek VigorConnect 1.6.0-B - Local File Inclusion POC 2025-08-01 | Draytek VigorConnect 1.6.0-B Draytek VigorConnect 1.6.0-B3 is susceptible to local file inclusion in the file download functional... CVE-2021-20124: Draytek VigorConnect 6.0-B3 - Local File Inclusion POC 2025-08-01 | Draytek VigorConnect 6.0-B3 Draytek VigorConnect 1.6.0-B3 is susceptible to local file inclusion in the file download functional... ShowDoc /server/index.php?s=/api/adminUpdate/download 文件上传漏洞(CVE-2021-36440) 无POC 2025-09-12 | ShowDoc ShowDoc 2.9.5版本存在一个高危的文件上传漏洞(CVE-2021-36440),该漏洞源于系统未能对上传文件的类型进行充分验证。攻击者可以绕过安全限制上传任意类型的危险文件,包括但不限于PH... CVE-2021-1497: Cisco HyperFlex HX Data Platform - Remote Command Execution POC 2025-09-01 | Cisco HyperFlex HX Data Platform Cisco HyperFlex HX contains multiple vulnerabilities in the web-based management interface that coul...