Vulnerabilities > CVE-2017-14942 - Files or Directories Accessible to External Parties vulnerability in Intelbras WRN 150 Firmware 1.0.1

047910
CVSS 9.8 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
intelbras
CWE-552
critical
exploit available

Summary

Intelbras WRN 150 devices allow remote attackers to read the configuration file, and consequently bypass authentication, via a direct request for cgi-bin/DownloadCfg/RouterCfm.cfg containing an admin:language=pt cookie.

Vulnerable Configurations

Part Description Count
OS
Intelbras
1
Hardware
Intelbras
1

Exploit-Db

idEDB-ID:42916