CVE-2025-55976

8.4

Intelbras · IWR 3000N

The Intelbras IWR 3000N router, version 1.9.8, exposes the Wi-Fi password in plaintext via an unauthenticated API endpoint, allowing local network users to retrieve sensitive credentials.

Executive summary

A critical vulnerability in the Intelbras IWR 3000N router allows unauthenticated local users to retrieve the Wi-Fi password, posing a significant risk to network security.

Vulnerability

The device fails to restrict access to the /api/wireless endpoint, which returns the Wi-Fi configuration, including the plaintext password, to any unauthenticated user connected to the local network.

Business impact

The exposure of Wi-Fi credentials enables unauthorized parties to gain full access to the internal network, potentially leading to data interception, unauthorized device control, and lateral movement. Given the high CVSS score of 8.4, this vulnerability represents a significant risk to the confidentiality and integrity of the local environment.

Remediation

Immediate Action: As no official patch is currently identified, restrict access to the administration interface and monitor the local network for unauthorized devices. Consider replacing or decommissioning the affected hardware if it remains unpatched by the vendor.

Proactive Monitoring: Review network access logs for suspicious requests directed at the /api/wireless endpoint and monitor for unexpected connections to the wireless network.

Compensating Controls: Implement network segmentation to isolate the management interface from general user traffic and enforce strict physical or logical access controls to the local network.

Exploitation status

Public Exploit Available: Yes, a published proof-of-concept exists; it is attributed to the technical write-up referenced by the researcher.

Analyst recommendation

The severity of this credential disclosure flaw necessitates immediate attention, as it undermines the primary security barrier of the wireless network. Administrators should treat this as a high-priority issue and restrict access to the affected devices until a formal firmware update is released by Intelbras.

More Intelbras CVEs

Sources