Vulnerability record · CVE-2017-14942 · published 30 September 2017
CVE-2017-14942: Intelbras WRN 150 router config file exposure enables auth bypass
Intelbras · Wrn 150 Firmware
Intelbras WRN 150 devices expose the configuration file at cgi-bin/DownloadCfg/RouterCfm.cfg to unauthenticated remote requests when an admin:language=pt cookie is supplied. Because the file contains credentials and device settings, reading it lets an attacker bypass authentication entirely. The flaw is remotely reachable and requires no privileges or user interaction.
Description
Intelbras WRN 150 devices allow remote attackers to read the configuration file, and consequently bypass authentication, via a direct request for cgi-bin/DownloadCfg/RouterCfm.cfg containing an admin:language=pt cookie.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with network reachability, no authentication, and public exploit code makes this a high-impact, easily exploitable flaw.
What it is
Intelbras WRN 150 devices expose the configuration file at cgi-bin/DownloadCfg/RouterCfm.cfg to unauthenticated remote requests when an admin:language=pt cookie is supplied. Because the file contains credentials and device settings, reading it lets an attacker bypass authentication entirely. The flaw is remotely reachable and requires no privileges or user interaction.
Impact
An attacker gains full read access to the router configuration, including administrative credentials, and can then bypass authentication to control the device. That enables further manipulation of network settings and traffic.
Attack surface
Reachable over the network via a direct HTTP request to cgi-bin/DownloadCfg/RouterCfm.cfg with a crafted admin:language=pt cookie. No authentication and no user interaction are required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).
Exploitation
Public exploit code exists (Exploit-DB 42916 and a linked write-up), and EPSS estimates a 60.9% 30-day exploitation probability (99.1st percentile). The CVE is not listed in CISA KEV, so no confirmed in-the-wild campaign is documented in this record.
What to do
- Apply the vendor firmware update for WRN 150 if one is available; the record does not specify a fixed version, so confirm with Intelbras.
- If no patch exists, restrict management access to a trusted LAN or management VLAN and block cgi-bin/DownloadCfg/RouterCfm.cfg from untrusted networks.
- Change default administrative credentials and rotate any credentials that may have been exposed via the config file.
- Disable remote management and UPnP exposure of the web interface where not required.
Detection
- Monitor HTTP requests for cgi-bin/DownloadCfg/RouterCfm.cfg, especially with an admin:language=pt cookie.
- Alert on config file downloads from router management interfaces by unexpected source IPs.
- Review router logs for authentication bypass patterns or anomalous admin sessions following config retrieval.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://whiteboyz.xyz/authentication-bypass-intelbras-wrn-150.html | ExploitURL Repurposed |
| https://www.exploit-db.com/exploits/42916/ | ExploitThird Party AdvisoryVDB Entry |
| http://whiteboyz.xyz/authentication-bypass-intelbras-wrn-150.html | ExploitURL Repurposed |
| https://www.exploit-db.com/exploits/42916/ | ExploitThird Party AdvisoryVDB Entry |
Track CVE-2017-14942 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-14942), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.