Ubee EVW3226 Cable Modem/Router Unauthenticated Backup File Disclosure Vulnerability

Vulnerability

A vulnerability exists in the Ubee EVW3226 cable modem/router in firmware versions through 1.0.20. The device improperly manages backup configuration files, storing them in the web root after generation for download. These files remain accessible without authentication until the next reboot. A remote attacker on the local network can directly request the 'Configuration_file.cfg' to obtain the backup archive. The unencrypted backup files contain sensitive information, including the plaintext admin password, which can lead to full compromise of the device.

Impact

Exploitation of this vulnerability allows for unauthorized access to the device's backup files, which contain sensitive information such as the admin password. This access can be used to gain full control over the router.

Reproduction

The vulnerability can be reproduced by requesting the 'Configuration_file.cfg' from the device's web server without authentication. This can be done using a simple HTTP GET request. Alternatively, if the backup file has already been downloaded, the same file can be uploaded to the device through the configuration restore function, which is also vulnerable to exploitation.

Added: Nov 14, 2025, 11:29 PM
Updated: Nov 14, 2025, 11:29 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
8.7
remediation
0.0
relevance
1.0
threat
6.4
urgency
2.9
incentive
5.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.