Record summary

CVE-2021-3017 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

The web interface on Intelbras WIN 300 and WRN 342 devices through 2021-01-04 allows remote attackers to discover credentials by reading the def_wirelesspassword line in the HTML source code.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryHIGHIntelbras WIN 300/WRN 342 - Credentials DisclosureCVSS 7.5

Intelbras WIN 300 and WRN 342 devices through 2021-01-04 allows remote attackers to discover credentials by reading the def_wirelesspassword line in the HTML source code.

Impact

An attacker can gain unauthorized access to the router's administrative interface and potentially compromise the entire network.

Remediation

Update the router firmware to the latest version, which includes a fix for the vulnerability.

Authorspikpikcu
Template tagscve2021cveexposurerouterintelbrasvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:h:intelbras:win_300:-:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

3