CVE-2021-3017 is a critical vulnerability affecting the web interfaces of Intelbras WIN 300 and WRN 342 devices. It allows unauthenticated remote attackers to discover Wi-Fi credentials by simply viewing the HTML source code, where the default wireless password is exposed. This vulnerability carries a CVSS score of 7.5 (High), indicating a severe risk due to its network-based attack vector, low complexity, and high impact on confidentiality. While there is no evidence of active exploitation or Metasploit modules, a Nuclei template exists for detection, and despite its high EPSS score and FAUCET Risk Score, it has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2021-01-04CPE matchmatch criteria | cpe:2.3:o:intelbras:win_300_firmware:*:*:*:*:*:*:*:* | ||
<= 2021-01-04CPE matchmatch criteria | cpe:2.3:o:intelbras:wrn_342_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.