Intelbras IWR 3000N
cpe:2.3:h:intelbras:iwr_3000n:*:*:*:*:*:*:*, +1 more
- 1.9.8
A vulnerability in the Intelbras IWR 3000N router running firmware 1.9.8 allows any unauthenticated user on the local network to access the Wi-Fi password in plaintext through the /api/wireless endpoint. This exposure of sensitive information could lead to unauthorized access to the wireless network.
Exploitation of this vulnerability allows any user on the local network to obtain the Wi-Fi password, leading to unauthorized access to the wireless network and potential man-in-the-middle attacks.
To reproduce this vulnerability, connect to the local network of the Intelbras IWR 3000N router. Then, send an unauthenticated HTTP GET request to the /api/wireless endpoint. The Wi-Fi password can be found in the JSON response under the 'key' or 'key1' field.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.