Intelbras Router RF 301K Authentication Bypass Vulnerability Allowing Unauthenticated Access to Configuration Files

Vulnerability

An authentication bypass vulnerability has been identified in the Intelbras Router RF 301K, specifically in firmware version 1.1.2. This vulnerability allows unauthenticated attackers to download sensitive router configuration files. Exploitation involves sending a specific HTTP GET request to the '/cgi-bin/DownloadCfg/RouterCfm.cfg' endpoint, bypassing authentication requirements.

Impact

Exploitation of this vulnerability could lead to unauthorized access to sensitive router configuration files, which may contain information that could be used to compromise the router or the network it is connected to.

Reproduction

To reproduce this vulnerability, send an HTTP GET request to the '/cgi-bin/DownloadCfg/RouterCfm.cfg' endpoint on a device running Intelbras Router RF 301K firmware version 1.1.2. This can be done using a tool like netcat or through a Python script that automates the request. The response should include the router's configuration file, indicating successful exploitation.

Added: Jan 28, 2026, 6:43 PM
Updated: Jan 28, 2026, 6:43 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
5.6
remediation
0.0
relevance
2.4
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.