CVE-2020-36963
7.5Intelbras · Router RF 301K
The Intelbras Router RF 301K contains an authentication bypass vulnerability in firmware version 1.1.2, allowing unauthenticated attackers to download sensitive configuration files via HTTP.
Executive summary
An unauthenticated authentication bypass vulnerability in Intelbras Router RF 301K firmware allows remote attackers to exfiltrate sensitive configuration files, posing a high risk to network privacy.
Vulnerability
The device fails to perform proper authentication checks for the configuration download function. An unauthenticated attacker can exploit this by sending a crafted HTTP GET request to the /cgi-bin/DownloadCfg/RouterCfm.cfg endpoint.
Business impact
Successful exploitation allows unauthorized access to sensitive router configuration files. These files typically contain critical information such as administrative credentials, Wi-Fi keys, and network topology details, which can be leveraged for further network compromise or interception of traffic. Given the CVSS score of 7.5, this high-severity vulnerability represents a significant risk to the confidentiality of network operations.
Remediation
Immediate Action: Update the affected router to the latest available firmware version provided by Intelbras that addresses this vulnerability.
Proactive Monitoring: Review device access logs for unusual HTTP GET requests directed at the /cgi-bin/DownloadCfg/ directory.
Compensating Controls: If a firmware update cannot be applied immediately, ensure the router management interface is not accessible from the public internet by configuring firewall rules or restricting access to trusted internal management subnets.
Exploitation status
Public Exploit Available: Yes, a functional proof-of-concept script is available on ExploitDB (EDB-ID: 49126).
Analyst recommendation
This vulnerability is highly accessible, requiring no authentication to expose sensitive infrastructure data. Administrators should prioritize updating the firmware on all impacted Intelbras RF 301K units to the latest version to close this security gap. If immediate patching is not feasible, ensure that the administrative interface is strictly isolated from external networks to prevent unauthorized access.
More Intelbras CVEs
Sources
Originally found and disclosed by Kaio Amaral, per the CVE Program record.
- ExploitDB-49126 Exploit / PoC
- Intelbras Official Homepage
- VulnCheck Advisory: Intelbras Router RF 301K 1.1.2 - Authentication Bypass Third-party advisory