VYPR
Vendor

Intelbras

Products
63
CVEs
62
Across products
100
Status
Private

Products

63
View all 63 products →

Recent CVEs

62
View all 62 CVEs →
  • CVE-2018-11094CriMay 15, 2018
    risk 0.70cvss 9.8epss 0.34

    An issue was discovered on Intelbras NCLOUD 300 1.0 devices. /cgi-bin/ExportSettings.sh, /goform/updateWPS, /goform/RebootSystem, and /goform/vpnBasicSettings do not require authentication. For example, when an HTTP POST request is made to /cgi-bin/ExportSettings.sh, the…

  • CVE-2017-14942CriSep 30, 2017
    risk 0.69cvss 9.8epss 0.61

    Intelbras WRN 150 devices allow remote attackers to read the configuration file, and consequently bypass authentication, via a direct request for cgi-bin/DownloadCfg/RouterCfm.cfg containing an admin:language=pt cookie.

  • CVE-2025-26063CriJul 31, 2025
    risk 0.64cvss 9.8epss 0.01

    An issue in Intelbras RX1500 v2.2.9 and RX3000 v1.0.11 allows unauthenticated attackers to execute arbitrary code via injecting a crafted payload into the ESSID name when creating a network.

  • CVE-2025-26062CriJul 31, 2025
    risk 0.64cvss 9.8epss 0.01

    An access control issue in Intelbras RX1500 v2.2.9 and RX3000 v1.0.11 allows unauthenticated attackers to access the router's settings file and obtain potentially sensitive information from the current settings.

  • CVE-2019-17600CriOct 15, 2019
    risk 0.64cvss 9.8epss 0.01

    Intelbras IWR 1000N 1.6.4 devices allow disclosure of the administrator login name and password because v1/system/user is mishandled.

  • CVE-2018-10369CriAug 15, 2018
    risk 0.64cvss 9.8epss 0.02

    A Cross-site scripting (XSS) vulnerability was discovered on Intelbras Win 240 V1.1.0 devices. An attacker can change the Admin Password without a Login.

  • CVE-2019-11416HigApr 22, 2019
    risk 0.61cvss 8.8epss 0.04

    A CSRF issue was discovered on Intelbras IWR 3000N 1.5.0 devices, leading to complete control of the router, as demonstrated by v1/system/user.

  • CVE-2022-40005HigDec 25, 2022
    risk 0.60cvss 8.8epss 0.35

    Intelbras WiFiber 120AC inMesh before 1-1-220826 allows command injection by authenticated users, as demonstrated by the /boaform/formPing6 and /boaform/formTracert URIs for ping and traceroute.

  • CVE-2021-32403HigMay 17, 2021
    risk 0.60cvss 8.8epss 0.02

    Intelbras Router RF 301K Firmware 1.1.2 is vulnerable to Cross Site Request Forgery (CSRF) due to lack of security mechanisms for token protection and unsafe inputs and modules.

  • CVE-2021-32402HigMay 17, 2021
    risk 0.57cvss 8.8epss 0.01

    Intelbras Router RF 301K Firmware 1.1.2 is vulnerable to Cross Site Request Forgery (CSRF) due to lack of validation and insecure configurations in inputs and modules.

  • CVE-2020-8829HigMay 5, 2020
    risk 0.57cvss 8.8epss 0.01

    CSRF on Intelbras CIP 92200 devices allows an attacker to access the panel and perform scraping or other analysis.

  • CVE-2019-19517HigMay 5, 2020
    risk 0.57cvss 8.8epss 0.01

    Intelbras RF1200 1.1.3 devices allow CSRF to bypass the login.html form, as demonstrated by launching a scrapy process.

  • CVE-2019-20004HigJan 5, 2020
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered on Intelbras IWR 3000N 1.8.7 devices. When the administrator password is changed from a certain client IP address, administrative authorization remains available to any client at that IP address, leading to complete control of the router.

  • CVE-2019-19995HigDec 26, 2019
    risk 0.57cvss 8.8epss 0.01

    A CSRF issue was discovered on Intelbras IWR 3000N 1.8.7 devices, leading to complete control of the router, as demonstrated by v1/system/user.

  • CVE-2019-11414HigApr 22, 2019
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered on Intelbras IWR 3000N 1.5.0 devices. When the administrator password is changed from a certain client IP address, administrative authorization remains available to any client at that IP address, leading to complete control of the router.

  • CVE-2018-12456HigOct 10, 2018
    risk 0.57cvss 8.8epss 0.01

    Intelbras NPLUG 1.0.0.14 wireless repeater devices have no CSRF token protection in the web interface, allowing attackers to perform actions such as changing the wireless SSID, rebooting the device, editing access control lists, or activating remote access.

  • CVE-2025-55976HigSep 10, 2025
    risk 0.55cvss 8.4epss 0.03

    Intelbras IWR 3000N 1.9.8 exposes the Wi-Fi password in plaintext via the /api/wireless endpoint. Any unauthenticated user on the local network can directly obtain the Wi-Fi network password by querying this endpoint.

  • CVE-2021-3017HigApr 14, 2021
    risk 0.54cvss 7.5epss 0.63

    The web interface on Intelbras WIN 300 and WRN 342 devices through 2021-01-04 allows remote attackers to discover credentials by reading the def_wirelesspassword line in the HTML source code.

  • CVE-2026-2564HigFeb 16, 2026
    risk 0.53cvss 8.1epss 0.00

    A security flaw has been discovered in Intelbras VIP 3260 Z IA 2.840.00IB005.0.T. Affected by this vulnerability is an unknown functionality of the file /OutsideCmd. The manipulation results in weak password recovery. It is possible to launch the attack remotely. Attacks of this…

  • CVE-2025-67070HigJan 9, 2026
    risk 0.53cvss 8.2epss 0.00

    A vulnerability exists in Intelbras CFTV IP NVD 9032 R Ftd V2.800.00IB00C.0.T, which allows an unauthenticated attacker to bypass the multi-factor authentication (MFA) mechanism during the password recovery process. This results in the ability to change the admin password and…