Intelbras records
51 published records for vendor intelbras.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 3
- With a fix record
- 7.8%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-352 Cross-Site Request Forgery (CSRF)9
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')9
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor4
- CWE-640 Weak Password Recovery Mechanism for Forgotten Password2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-284 Improper Access Control2
The weakness classes this vendor ships most often: where to look.
CWEAll records
51 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
57Plan | CVE-2017-14942Proof of concept | Intelbras WRN 150 devices allow remote attackers to read the configuration file, and consequently bypass authentication, via a direct requesintelbras · wrn 150 firmware · CWE-552 | Critical9.8 | — | 60.9% | Sep 29, 2017 |
49Plan | CVE-2021-3017Proof of concept | The web interface on Intelbras WIN 300 and WRN 342 devices through 2021-01-04 allows remote attackers to discover credentials by reading theintelbras · win 300 firmware | High7.5 | — | 63.0% | Apr 14, 2021 |
49Plan | CVE-2018-11094Proof of concept | An issue was discovered on Intelbras NCLOUD 300 1.0 devices.intelbras · ncloud 300 firmware · CWE-798 | Critical9.8 | — | 33.4% | May 15, 2018 |
46Plan | CVE-2022-40005No exploit | Intelbras WiFiber 120AC inMesh before 1-1-220826 allows command injection by authenticated users, as demonstrated by the /boaform/formPing6 intelbras · wifiber 120ac inmesh firmware · CWE-78 | High8.8 | — | 35.0% | Dec 25, 2022 |
41Plan | CVE-2023-36144Proof of concept | An authentication bypass in Intelbras Switch SG 2404 MR in firmware 1.00.54 allows an unauthenticated attacker to download the backup file ointelbras · sg 2404 mr firmware · CWE-862 | High7.5 | — | 36.5% | Jun 30, 2023 |
40Plan | CVE-2018-10369No exploit | A Cross-site scripting (XSS) vulnerability was discovered on Intelbras Win 240 V1.1.0 devices.intelbras · win 240 firmware · CWE-79 | Critical9.8 | — | 1.9% | Aug 15, 2018 |
39Monitor | CVE-2025-26063No exploit | An issue in Intelbras RX1500 v2.2.9 and RX3000 v1.0.11 allows unauthenticated attackers to execute arbitrary code via injecting a crafted paintelbras · rx 1500 firmware · CWE-77 | Critical9.8 | — | 1.3% | Jul 31, 2025 |
39Monitor | CVE-2019-17600No exploit | Intelbras IWR 1000N 1.6.4 devices allow disclosure of the administrator login name and password because v1/system/user is mishandled.intelbras · iwr 1000n firmware · CWE-352 | Critical9.8 | — | 1.2% | Oct 15, 2019 |
39Monitor | CVE-2025-26062No exploit | An access control issue in Intelbras RX1500 v2.2.9 and RX3000 v1.0.11 allows unauthenticated attackers to access the router's settings file intelbras · rx 1500 firmware · CWE-284 | Critical9.8 | — | 1.1% | Jul 31, 2025 |
36Monitor | CVE-2019-11416Proof of concept | A CSRF issue was discovered on Intelbras IWR 3000N 1.5.0 devices, leading to complete control of the router, as demonstrated by v1/system/usintelbras · iwr 3000n firmware · CWE-352 | High8.8 | — | 3.9% | Apr 22, 2019 |
36Monitor | CVE-2021-32403Proof of concept | Intelbras Router RF 301K Firmware 1.1.2 is vulnerable to Cross Site Request Forgery (CSRF) due to lack of security mechanisms for token protintelbras · rf 301k firmware · CWE-352 | High8.8 | — | 2.5% | May 17, 2021 |
35Monitor | CVE-2019-11414No exploit | An issue was discovered on Intelbras IWR 3000N 1.5.0 devices.intelbras · iwr 3000n firmware · CWE-640 | High8.8 | — | 1.3% | Apr 22, 2019 |
35Monitor | CVE-2019-20004No exploit | An issue was discovered on Intelbras IWR 3000N 1.8.7 devices.intelbras · iwr 3000n firmware · CWE-640 | High8.8 | — | 1.2% | Jan 5, 2020 |
35Monitor | CVE-2018-12456No exploit | Intelbras NPLUG 1.0.0.14 wireless repeater devices have no CSRF token protection in the web interface, allowing attackers to perform actionsintelbras · nplug firmware · CWE-352 | High8.8 | — | 0.9% | Oct 10, 2018 |
35Monitor | CVE-2019-19995No exploit | A CSRF issue was discovered on Intelbras IWR 3000N 1.8.7 devices, leading to complete control of the router, as demonstrated by v1/system/usintelbras · iwr 3000n firmware · CWE-352 | High8.8 | — | 0.7% | Dec 26, 2019 |
35Monitor | CVE-2019-19517No exploit | Intelbras RF1200 1.1.3 devices allow CSRF to bypass the login.html form, as demonstrated by launching a scrapy process.intelbras · action rf 1200 firmware · CWE-352 | High8.8 | — | 0.5% | May 5, 2020 |
35Monitor | CVE-2021-32402No exploit | Intelbras Router RF 301K Firmware 1.1.2 is vulnerable to Cross Site Request Forgery (CSRF) due to lack of validation and insecure configuratintelbras · rf 301k firmware · CWE-352 | High8.8 | — | 0.5% | May 17, 2021 |
35Monitor | CVE-2020-8829No exploit | CSRF on Intelbras CIP 92200 devices allows an attacker to access the panel and perform scraping or other analysis.intelbras · cip 92200 firmware · CWE-352 | High8.8 | — | 0.5% | May 5, 2020 |
34Monitor | CVE-2019-11415Proof of concept | An issue was discovered on Intelbras IWR 3000N 1.5.0 devices.intelbras · iwr 3000n firmware | High7.5 | — | 13.7% | Apr 22, 2019 |
34Monitor | CVE-2018-12455Proof of concept | Intelbras NPLUG 1.0.0.14 wireless repeater devices have a critical vulnerability that allows an attacker to authenticate in the web interfacintelbras · nplug firmware · CWE-287 | High8.1 | — | 5.9% | Oct 10, 2018 |
34Monitor | CVE-2025-55976No exploit | Intelbras IWR 3000N 1.9.8 exposes the Wi-Fi password in plaintext via the /api/wireless endpoint.intelbras · iwr 3000n firmware · CWE-200 | High8.4 | — | 3.2% | Sep 10, 2025 |
34Monitor | CVE-2024-9325No exploit | Intelbras InControl incontrol-service-watchdog.exe unquoted search pathintelbras · incontrol web · CWE-426 | High8.5 | — | 0.3% | Sep 29, 2024 |
34Monitor | CVE-2024-6080No exploit | Intelbras InControl incontrolWebcam Service unquoted search pathintelbras · incontrol · CWE-426 | High8.5 | — | 0.2% | Jun 17, 2024 |
32Monitor | CVE-2019-19142Proof of concept | Intelbras WRN240 devices do not require authentication to replace the firmware via a POST request to the incoming/Firmware.cfg URI.intelbras · wrn 240 firmware · CWE-306 | High7.5 | — | 7.8% | Jan 16, 2020 |
32Monitor | CVE-2024-22773No exploit | Intelbras Action RF 1200 routers 1.2.2 and earlier and Action RG 1200 routers 2.1.7 and earlier expose the Password in Cookie resulting in Lintelbras · action rf 1200 firmware · CWE-922 | High8.1 | — | 1.0% | Feb 5, 2024 |
- CVE-2017-1494257Plan
Intelbras WRN 150 devices allow remote attackers to read the configuration file, and consequently bypass authentication, via a direct reques
CriticalCVSS 9.8Proof of conceptEPSS 61%intelbras · wrn 150 firmwareSep 29, 2017
- CVE-2021-301749Plan
The web interface on Intelbras WIN 300 and WRN 342 devices through 2021-01-04 allows remote attackers to discover credentials by reading the
HighCVSS 7.5Proof of conceptEPSS 63%intelbras · win 300 firmwareApr 14, 2021
- CVE-2018-1109449Plan
An issue was discovered on Intelbras NCLOUD 300 1.0 devices.
CriticalCVSS 9.8Proof of conceptEPSS 33%intelbras · ncloud 300 firmwareMay 15, 2018
- CVE-2022-4000546Plan
Intelbras WiFiber 120AC inMesh before 1-1-220826 allows command injection by authenticated users, as demonstrated by the /boaform/formPing6
HighCVSS 8.8No exploitEPSS 35%intelbras · wifiber 120ac inmesh firmwareDec 25, 2022
- CVE-2023-3614441Plan
An authentication bypass in Intelbras Switch SG 2404 MR in firmware 1.00.54 allows an unauthenticated attacker to download the backup file o
HighCVSS 7.5Proof of conceptEPSS 37%intelbras · sg 2404 mr firmwareJun 30, 2023
- CVE-2018-1036940Plan
A Cross-site scripting (XSS) vulnerability was discovered on Intelbras Win 240 V1.1.0 devices.
CriticalCVSS 9.8No exploitEPSS 2%intelbras · win 240 firmwareAug 15, 2018
- CVE-2025-2606339Monitor
An issue in Intelbras RX1500 v2.2.9 and RX3000 v1.0.11 allows unauthenticated attackers to execute arbitrary code via injecting a crafted pa
CriticalCVSS 9.8No exploitEPSS 1%intelbras · rx 1500 firmwareJul 31, 2025
- CVE-2019-1760039Monitor
Intelbras IWR 1000N 1.6.4 devices allow disclosure of the administrator login name and password because v1/system/user is mishandled.
CriticalCVSS 9.8No exploitEPSS 1%intelbras · iwr 1000n firmwareOct 15, 2019
- CVE-2025-2606239Monitor
An access control issue in Intelbras RX1500 v2.2.9 and RX3000 v1.0.11 allows unauthenticated attackers to access the router's settings file
CriticalCVSS 9.8No exploitEPSS 1%intelbras · rx 1500 firmwareJul 31, 2025
- CVE-2019-1141636Monitor
A CSRF issue was discovered on Intelbras IWR 3000N 1.5.0 devices, leading to complete control of the router, as demonstrated by v1/system/us
HighCVSS 8.8Proof of conceptEPSS 4%intelbras · iwr 3000n firmwareApr 22, 2019
- CVE-2021-3240336Monitor
Intelbras Router RF 301K Firmware 1.1.2 is vulnerable to Cross Site Request Forgery (CSRF) due to lack of security mechanisms for token prot
HighCVSS 8.8Proof of conceptEPSS 2%intelbras · rf 301k firmwareMay 17, 2021
- CVE-2019-1141435Monitor
An issue was discovered on Intelbras IWR 3000N 1.5.0 devices.
HighCVSS 8.8No exploitEPSS 1%intelbras · iwr 3000n firmwareApr 22, 2019
- CVE-2019-2000435Monitor
An issue was discovered on Intelbras IWR 3000N 1.8.7 devices.
HighCVSS 8.8No exploitEPSS 1%intelbras · iwr 3000n firmwareJan 5, 2020
- CVE-2018-1245635Monitor
Intelbras NPLUG 1.0.0.14 wireless repeater devices have no CSRF token protection in the web interface, allowing attackers to perform actions
HighCVSS 8.8No exploitEPSS 1%intelbras · nplug firmwareOct 10, 2018
- CVE-2019-1999535Monitor
A CSRF issue was discovered on Intelbras IWR 3000N 1.8.7 devices, leading to complete control of the router, as demonstrated by v1/system/us
HighCVSS 8.8No exploitEPSS 1%intelbras · iwr 3000n firmwareDec 26, 2019
- CVE-2019-1951735Monitor
Intelbras RF1200 1.1.3 devices allow CSRF to bypass the login.html form, as demonstrated by launching a scrapy process.
HighCVSS 8.8No exploitEPSS 1%intelbras · action rf 1200 firmwareMay 5, 2020
- CVE-2021-3240235Monitor
Intelbras Router RF 301K Firmware 1.1.2 is vulnerable to Cross Site Request Forgery (CSRF) due to lack of validation and insecure configurat
HighCVSS 8.8No exploitEPSS 1%intelbras · rf 301k firmwareMay 17, 2021
- CVE-2020-882935Monitor
CSRF on Intelbras CIP 92200 devices allows an attacker to access the panel and perform scraping or other analysis.
HighCVSS 8.8No exploitEPSS 1%intelbras · cip 92200 firmwareMay 5, 2020
- CVE-2019-1141534Monitor
An issue was discovered on Intelbras IWR 3000N 1.5.0 devices.
HighCVSS 7.5Proof of conceptEPSS 14%intelbras · iwr 3000n firmwareApr 22, 2019
- CVE-2018-1245534Monitor
Intelbras NPLUG 1.0.0.14 wireless repeater devices have a critical vulnerability that allows an attacker to authenticate in the web interfac
HighCVSS 8.1Proof of conceptEPSS 6%intelbras · nplug firmwareOct 10, 2018
- CVE-2025-5597634Monitor
Intelbras IWR 3000N 1.9.8 exposes the Wi-Fi password in plaintext via the /api/wireless endpoint.
HighCVSS 8.4No exploitEPSS 3%intelbras · iwr 3000n firmwareSep 10, 2025
- CVE-2024-932534Monitor
Intelbras InControl incontrol-service-watchdog.exe unquoted search path
HighCVSS 8.5No exploitEPSS 0%intelbras · incontrol webSep 29, 2024
- CVE-2024-608034Monitor
Intelbras InControl incontrolWebcam Service unquoted search path
HighCVSS 8.5No exploitEPSS 0%intelbras · incontrolJun 17, 2024
- CVE-2019-1914232Monitor
Intelbras WRN240 devices do not require authentication to replace the firmware via a POST request to the incoming/Firmware.cfg URI.
HighCVSS 7.5Proof of conceptEPSS 8%intelbras · wrn 240 firmwareJan 16, 2020
- CVE-2024-2277332Monitor
Intelbras Action RF 1200 routers 1.2.2 and earlier and Action RG 1200 routers 2.1.7 and earlier expose the Password in Cookie resulting in L
HighCVSS 8.1No exploitEPSS 1%intelbras · action rf 1200 firmwareFeb 5, 2024