← Back to CVE List
Vulnerability Intelligence Report

CVE-2021-20126

Draytek VigorConnect 1.6.0-B3 lacks cross-site request forgery protections and does not sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

No Active Exploit Signals
CVSS Base Score
8.8
HIGH
EPSS Probability:0.61%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Affected Products & Versions

Vendor Product Affected Versions
draytek vigorconnect 1.6.0

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
0.612%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityTenable Network Security, Inc. · Vendor · USA
Reserved2020-12-17T00:00:00
Published2021-10-13T15:48:15
Last Updated2024-08-03T17:30:07

LINK COPIED TO CLIPBOARD