Exploitation Summary
EIP tracks 1 public exploit for CVE-2017-14219. PoCs published by Elber Tavares.
AI-analyzed exploit summary This exploit demonstrates a persistent XSS vulnerability in Intelbras WRN 240 routers. It injects a malicious script via the SSID field, which exfiltrates credentials from the router's admin page to a remote server.
Description
XSS (persistent) on the Intelbras Wireless N 150Mbps router with firmware WRN 240 allows attackers to steal wireless credentials without being connected to the network, related to userRpm/popupSiteSurveyRpm.htm and userRpm/WlanSecurityRpm.htm. The attack vector is a crafted ESSID, as demonstrated by an "airbase-ng -e" command.
Exploits (1)
This exploit demonstrates a persistent XSS vulnerability in Intelbras WRN 240 routers. It injects a malicious script via the SSID field, which exfiltrates credentials from the router's admin page to a remote server.
References (2)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N