CVE-2020-36963: Intelbras Router RF 301K 1.1.2 - Authentication Bypass
Intelbras Router RF 301K firmware version 1.1.2 contains an authentication bypass vulnerability that allows unauthenticated attackers to download router configuration files. Attackers can send a specific HTTP GET request to /cgi-bin/DownloadCfg/RouterCfm.cfg to retrieve sensitive router configuration without authentication.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Intelbras Router RF 301Kto a version that resolves this vulnerability.Fixed in 1.1.2
Event History
Frequently Asked Questions
What is the severity of CVE-2020-36963?
CVE-2020-36963 is classified as a critical vulnerability due to its ability to allow unauthenticated attackers to access sensitive configuration files.
How do I fix CVE-2020-36963?
To fix CVE-2020-36963, update the firmware of the Intelbras Router RF 301K to the latest version provided by the manufacturer.
What does CVE-2020-36963 allow an attacker to do?
CVE-2020-36963 allows an attacker to bypass authentication and download sensitive router configuration files.
Which device is affected by CVE-2020-36963?
CVE-2020-36963 affects the Intelbras Router RF 301K running firmware version 1.1.2.
How can I identify if my router is vulnerable to CVE-2020-36963?
You can identify if your router is vulnerable to CVE-2020-36963 by checking if it is running firmware version 1.1.2 or lower.