Vulnerabilities
Vulnerable Software
Intelbras:  Security Vulnerabilities
An issue was discovered on Intelbras IWR 3000N 1.8.7 devices. A malformed login request allows remote attackers to cause a denial of service (reboot), as demonstrated by JSON misparsing of the \""} string to v1/system/login.
CVSS Score
7.5
EPSS Score
0.009
Published
2019-12-26
Intelbras IWR 3000N 1.8.7 devices allow disclosure of the administrator login name and password because v1/system/user is mishandled, a related issue to CVE-2019-17600.
CVSS Score
7.2
EPSS Score
0.005
Published
2019-12-05
Intelbras WRN 150 1.0.18 devices allow CSRF via GO=system_password.asp to the goform/SysToolChangePwd URI to change a password.
CVSS Score
6.5
EPSS Score
0.008
Published
2019-12-02
An issue was discovered on Intelbras WRN 150 1.0.17 devices. There is stored XSS in the Service Name tab of the WAN configuration screen, leading to a denial of service (inability to change the configuration).
CVSS Score
6.1
EPSS Score
0.003
Published
2019-11-07
Intelbras IWR 1000N 1.6.4 devices allow disclosure of the administrator login name and password because v1/system/user is mishandled.
CVSS Score
9.8
EPSS Score
0.002
Published
2019-10-15
An issue was discovered on Intelbras IWR 3000N 1.5.0 devices. When the administrator password is changed from a certain client IP address, administrative authorization remains available to any client at that IP address, leading to complete control of the router.
CVSS Score
8.8
EPSS Score
0.004
Published
2019-04-22
An issue was discovered on Intelbras IWR 3000N 1.5.0 devices. A malformed login request allows remote attackers to cause a denial of service (reboot), as demonstrated by JSON misparsing of the \""} string to v1/system/login.
CVSS Score
7.5
EPSS Score
0.344
Published
2019-04-22
A CSRF issue was discovered on Intelbras IWR 3000N 1.5.0 devices, leading to complete control of the router, as demonstrated by v1/system/user.
CVSS Score
8.8
EPSS Score
0.019
Published
2019-04-22
Intelbras NPLUG 1.0.0.14 devices have XSS via a crafted SSID that is received via a network broadcast.
CVSS Score
6.1
EPSS Score
0.002
Published
2018-10-10
Intelbras NPLUG 1.0.0.14 wireless repeater devices have a critical vulnerability that allows an attacker to authenticate in the web interface just by using "admin:" as the name of a cookie.
CVSS Score
8.1
EPSS Score
0.453
Published
2018-10-10


Contact Us

Shodan ® - All rights reserved