Vulnerability record · CVE-2017-14219 · published 7 September 2017
CVE-2017-14219: Intelbras wrn 240 firmware cross-site scripting vulnerability
Intelbras · Wrn 240 Firmware
XSS (persistent) on the Intelbras Wireless N 150Mbps router with firmware WRN 240 allows attackers to steal wireless credentials without being connected to the network, related to userRpm/popupSiteSurveyRpm.htm and userRpm/WlanSecurityRpm.htm. The attack vector is a crafted ESSID, as demonstrated by an "airbase-ng -e" command.
Description
XSS (persistent) on the Intelbras Wireless N 150Mbps router with firmware WRN 240 allows attackers to steal wireless credentials without being connected to the network, related to userRpm/popupSiteSurveyRpm.htm and userRpm/WlanSecurityRpm.htm. The attack vector is a crafted ESSID, as demonstrated by an "airbase-ng -e" command.
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://whiteboyz.xyz/xss-roteador-intelbras-wrn-240.html | ExploitThird Party AdvisoryURL Repurposed |
| https://www.exploit-db.com/exploits/42633/ | ExploitThird Party AdvisoryVDB Entry |
| http://whiteboyz.xyz/xss-roteador-intelbras-wrn-240.html | ExploitThird Party AdvisoryURL Repurposed |
| https://www.exploit-db.com/exploits/42633/ | ExploitThird Party AdvisoryVDB Entry |
Track CVE-2017-14219 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-14219), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.