CVE-2018-11094: Intelbras Ncloud 300 Firmware

Critical severity, CVSS 9.8. EPSS: 33.4% chance of exploitation in the next 30 days.

An issue was discovered on Intelbras NCLOUD 300 1.0 devices. /cgi-bin/ExportSettings.sh, /goform/updateWPS, /goform/RebootSystem, and /goform/vpnBasicSettings do not require authentication. For example, when an HTTP POST request is made to /cgi-bin/ExportSettings.sh, the username, password, and other details are retrieved.

Affected products

  • Intelbras Ncloud 300 Firmware: version 1.0 only

Published 2018-05-15. Last modified 2026-06-17.