CVE-2020-29138: Sagemcom F@st 3486 Router Firmware
Medium severity, CVSS 5.3. EPSS: 1.1% chance of exploitation in the next 30 days.
Incorrect Access Control in the configuration backup path in SAGEMCOM F@ST3486 NET DOCSIS 3.0, software NET_4.109.0, allows remote unauthenticated users to download the router configuration file via the /backupsettings.conf URI, when any valid session is running.
Affected products
- Sagemcom F@st 3486 Router Firmware: version 4.109.0 only
Published 2020-11-27. Last modified 2026-06-17.