Intelbras RX1500 Router Incorrect Access Control Vulnerability Allowing Unauthorized Firmware Upload and Command Execution

Vulnerability

An incorrect access control vulnerability has been identified in the Intelbras RX1500 Router, specifically in versions through 2.2.17. The issue resides in the FirmwareUpload and GetFirmwareValidation functions, which can be accessed without proper authorization. This vulnerability allows attackers to forge a firmware package, upload it to the router, and execute commands by exploiting the uploaded firmware.

Impact

Exploitation of this vulnerability could lead to unauthorized firmware uploads and execution of arbitrary commands on the router.

Reproduction

To reproduce this vulnerability, send a POST request to the router's HNAP1 interface with a forged firmware package. Include the 'SOAPAction' header to specify the 'FirmwareUpload' function. After uploading the malicious firmware, use the 'GetFirmwareValidation' function to trigger the execution of commands embedded in the uploaded firmware package.

Added: Sep 1, 2025, 7:22 PM
Updated: Sep 1, 2025, 7:22 PM

Vulnerability Rating

Custom Algorithm
spread
4.5
impact
7.5
exploitability
9.1
remediation
0.0
relevance
0.2
threat
6.4
urgency
2.9
incentive
9.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.