CVE-2021-3017
Intelbras WIN 300/WRN 342 - Credentials Disclosure
Record summary
CVE-2021-3017 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.
Description
The web interface on Intelbras WIN 300 and WRN 342 devices through 2021-01-04 allows remote attackers to discover credentials by reading the def_wirelesspassword line in the HTML source code.
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryHIGHIntelbras WIN 300/WRN 342 - Credentials DisclosureCVSS 7.5
Intelbras WIN 300 and WRN 342 devices through 2021-01-04 allows remote attackers to discover credentials by reading the def_wirelesspassword line in the HTML source code.
Impact
An attacker can gain unauthorized access to the router's administrative interface and potentially compromise the entire network.
Remediation
Update the router firmware to the latest version, which includes a fix for the vulnerability.
Source: ProjectDiscovery