CVE-2018-9010: Intelbras TIP200 Firmware

High severity, CVSS 7.2. EPSS: 9.7% chance of exploitation in the next 30 days.

Intelbras TELEFONE IP TIP200/200 LITE 60.0.75.29 devices allow remote authenticated admins to read arbitrary files via the /cgi-bin/cgiServer.exx page parameter, aka absolute path traversal. In some cases, authentication can be achieved via the admin account with its default admin password.

Affected products

  • Intelbras TIP200 Firmware: version 60.0.75.29 only
  • Intelbras TIP200LITE Firmware: version 60.0.75.29 only

Published 2018-03-25. Last modified 2026-06-17.