S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated May 31, 2025

CVE-2020-13886 Scanner

CVE-2020-13886 Scanner - Local File Inclusion (LFI) vulnerability in Intelbras TIP 200/200 LITE/300

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
3.4k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2020-13886
5.3
CVSS

Intelbras TIP 200 60.61.75.15, TIP 200 LITE 60.61.75.15, and TIP 300 65.61.75.22 devices allow cgi-bin/cgiServer.exx?page=../ Directory Traversal.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

Intelbras TIP 200/200 LITE/300 is widely used in VoIP communication systems for small to medium-sized businesses. It is well-regarded for providing reliable and efficient telecommunication solutions. These devices are mainly deployed in corporate environments to facilitate office communication. They are equipped with advanced features including call management, VoIP support, and conferencing capability. Designed to be user-friendly, these devices require minimal setup time while supporting a range of telecommunication functions. Intelbras products are known for their quality and technical support, making them a popular choice in the telecom industry.

The Local File Inclusion (LFI) vulnerability detected in Intelbras TIP 200/200 LITE/300 allows unauthorized users to include files from the system's local file structure. This vulnerability can be used to access sensitive files within the system like password files. The potential attack leverages a flaw in the handling of paths within a URL, which allows an attacker to execute arbitrary code or disclose sensitive data. Unsanctioned access to configuration files can escalate into broader security threats. Proper awareness and patching of devices are required to prevent exploitation of this vulnerability. Mitigating LFI vulnerabilities is a critical requirement for maintaining network security.

The technical details of this vulnerability revolve around the 'page' parameter within the /cgi-bin/cgiServer.exx endpoint. When manipulated, this parameter can trigger a local file inclusion due to improper validation. An attacker can exploit this gap by using a crafted URL to traverse directories and access files like /etc/passwd. The status code 200 and presence of 'root:.*:0:0:' pattern confirm a successful attack. Ensuring proper input validation and updating endpoint configurations can mitigate the risk of LFI vulnerabilities. It is crucial for affected devices using this endpoint to apply security patches made available by manufacturers.

If exploited by malicious entities, this LFI vulnerability could lead to unauthorized access to sensitive information, potentially resulting in escalating privileges or executing unauthorized operations. Attackers could retrieve critical configuration files or sensitive data, undermining the device's security framework. This breach can facilitate further attacks on the network, potentially compromising the confidentiality and integrity of the system. The risk extends to unauthorized manipulation of device configurations, impacting overall security and operation continuity. Immediate responses and patching are essential to prevent unauthorized exploitation.

REFERENCES

Solution Advice
  • Update the device firmware to the latest version provided by Intelbras.
  • Implement input validation and sanitation to prevent improper URL handling.
  • Regularly audit and monitor systems for suspicious activity.
  • Restrict file permissions to limit sensitive file access.
  • Enable security features provided by the manufacturer to enhance device protection.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2020-13886 Scanner - Local File Inclusion (LFI) vulnerability in Intelbras TIP 200/200 LITE/300 | S4E