CVE-2020-29138: Sagemcom F@st 3486 Router Firmware

Medium severity, CVSS 5.3. EPSS: 1.1% chance of exploitation in the next 30 days.

Incorrect Access Control in the configuration backup path in SAGEMCOM F@ST3486 NET DOCSIS 3.0, software NET_4.109.0, allows remote unauthenticated users to download the router configuration file via the /backupsettings.conf URI, when any valid session is running.

Affected products

  • Sagemcom F@st 3486 Router Firmware: version 4.109.0 only

Published 2020-11-27. Last modified 2026-06-17.