CVE-2020-36963: Intelbras Router Rf 301k

High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.

Intelbras Router RF 301K firmware version 1.1.2 contains an authentication bypass vulnerability that allows unauthenticated attackers to download router configuration files. Attackers can send a specific HTTP GET request to /cgi-bin/DownloadCfg/RouterCfm.cfg to retrieve sensitive router configuration without authentication.

Affected products

Published 2026-01-28. Last modified 2026-06-17.