Record summary

CVE-2020-36963 has a selected CVSS score of 8.7 (high); EIP currently links 1 catalogued exploit.

Description

Intelbras Router RF 301K firmware version 1.1.2 contains an authentication bypass vulnerability that allows unauthenticated attackers to download router configuration files. Attackers can send a specific HTTP GET request to /cgi-bin/DownloadCfg/RouterCfm.cfg to retrieve sensitive router configuration without authentication.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 28, 2026 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE Listfirmware version 1.1.2affected

Proofs of concept

1

Catalogued exploits

ExploitDBIntelbras Router RF 301K 1.1.2 - Authentication BypassExploitDB exploitby Kaio AmaralNot analyzed1 file
ExploitDB

PoC details

References

4