Intelbras manufactures a focused line of networking and wireless products for small-to-medium enterprise and consumer markets, with vulnerabilities clustering in routing and access-control appliances such as the IWR 3000N and RX 1500 series. The vendor's disclosures skew toward serious outcomes, with an elevated share reaching critical severity and a strong tendency toward public exploit availability, reflecting the appeal of internet-facing network devices for rapid weaponization and deployment. Recurring exposure centers on web-management interfaces and firmware across these product lines, driven by weakness classes including cross-site request forgery, cross-site scripting, improper access control, and information disclosure—all characteristic of embedded device firmware with minimal input validation and insufficient session-protection mechanisms. Defenders should prioritize inventory and segmentation of these appliances, especially those exposed to untrusted networks, and treat firmware updates for affected models as urgent. Current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Intelbras over time
Signals from CVEs in this vendor scope (50 CVEs).
50 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-14942CRITICAL Intelbras WRN 150 devices allow remote attackers to read the configuration file, and consequently bypass authentication, via a direct request for cgi-bin/DownloadCfg/RouterCfm.cfg | Sep 30, 2017 | 9.8 | 74 | NO | YES |
CVE-2021-3017HIGH The web interface on Intelbras WIN 300 and WRN 342 devices through 2021-01-04 allows remote attackers to discover credentials by reading the def_wirelesspassword line in the HTML s | Apr 14, 2021 | 7.5 | 68 | NO | YES |
CVE-2018-11094CRITICAL An issue was discovered on Intelbras NCLOUD 300 1.0 devices. /cgi-bin/ExportSettings.sh, /goform/updateWPS, /goform/RebootSystem, and /goform/vpnBasicSettings do not require authen | May 15, 2018 | 9.8 | 59 | NO | YES |
CVE-2023-36144HIGH An authentication bypass in Intelbras Switch SG 2404 MR in firmware 1.00.54 allows an unauthenticated attacker to download the backup file of the device, exposing critical informat | Jun 30, 2023 | 7.5 | 54 | NO | YES |
CVE-2022-40005HIGH Intelbras WiFiber 120AC inMesh before 1-1-220826 allows command injection by authenticated users, as demonstrated by the /boaform/formPing6 and /boaform/formTracert URIs for ping a | Dec 25, 2022 | 8.8 | 47 | NO | NO |
CVE-2019-11415HIGH An issue was discovered on Intelbras IWR 3000N 1.5.0 devices. A malformed login request allows remote attackers to cause a denial of service (reboot), as demonstrated by JSON mispa | Apr 22, 2019 | 7.5 | 41 | NO | YES |
CVE-2019-11416HIGH A CSRF issue was discovered on Intelbras IWR 3000N 1.5.0 devices, leading to complete control of the router, as demonstrated by v1/system/user. | Apr 22, 2019 | 8.8 | 39 | NO | YES |
CVE-2021-32403HIGH Intelbras Router RF 301K Firmware 1.1.2 is vulnerable to Cross Site Request Forgery (CSRF) due to lack of security mechanisms for token protection and unsafe inputs and modules. | May 17, 2021 | 8.8 | 38 | NO | YES |
CVE-2020-24285HIGH INTELBRAS TELEFONE IP TIP200 version 60.61.75.22 allows an attacker to obtain sensitive information through /cgi-bin/cgiServer.exx. | Apr 12, 2021 | 7.5 | 38 | NO | YES |
CVE-2018-12455HIGH Intelbras NPLUG 1.0.0.14 wireless repeater devices have a critical vulnerability that allows an attacker to authenticate in the web interface just by using "admin:" as the name of | Oct 10, 2018 | 8.1 | 38 | NO | YES |
Signals from CVEs in this vendor scope (50 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Intelbras.
Media articles that mention a CVE ID that affects a product developed by Intelbras — matched by CVE ID, not by vendor name.