← Vulnerability feed

Vulnerability record · CVE-2017-14942 · published 30 September 2017

CVE-2017-14942: Intelbras WRN 150 router config file exposure enables auth bypass

Intelbras · Wrn 150 Firmware

Intelbras WRN 150 devices expose the configuration file at cgi-bin/DownloadCfg/RouterCfm.cfg to unauthenticated remote requests when an admin:language=pt cookie is supplied. Because the file contains credentials and device settings, reading it lets an attacker bypass authentication entirely. The flaw is remotely reachable and requires no privileges or user interaction.

9.8 CVSS 3.0 Critical EPSS 61% · top 0.9% CWE-552 · CWE-552
9.8CVSS 3.0 base score, v2 7.5
61%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

Intelbras WRN 150 devices allow remote attackers to read the configuration file, and consequently bypass authentication, via a direct request for cgi-bin/DownloadCfg/RouterCfm.cfg containing an admin:language=pt cookie.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

critical priorityCVSS 9.8 with network reachability, no authentication, and public exploit code makes this a high-impact, easily exploitable flaw.

What it is

Intelbras WRN 150 devices expose the configuration file at cgi-bin/DownloadCfg/RouterCfm.cfg to unauthenticated remote requests when an admin:language=pt cookie is supplied. Because the file contains credentials and device settings, reading it lets an attacker bypass authentication entirely. The flaw is remotely reachable and requires no privileges or user interaction.

Impact

An attacker gains full read access to the router configuration, including administrative credentials, and can then bypass authentication to control the device. That enables further manipulation of network settings and traffic.

Attack surface

Reachable over the network via a direct HTTP request to cgi-bin/DownloadCfg/RouterCfm.cfg with a crafted admin:language=pt cookie. No authentication and no user interaction are required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).

Exploitation

Public exploit code exists (Exploit-DB 42916 and a linked write-up), and EPSS estimates a 60.9% 30-day exploitation probability (99.1st percentile). The CVE is not listed in CISA KEV, so no confirmed in-the-wild campaign is documented in this record.

What to do

  • Apply the vendor firmware update for WRN 150 if one is available; the record does not specify a fixed version, so confirm with Intelbras.
  • If no patch exists, restrict management access to a trusted LAN or management VLAN and block cgi-bin/DownloadCfg/RouterCfm.cfg from untrusted networks.
  • Change default administrative credentials and rotate any credentials that may have been exposed via the config file.
  • Disable remote management and UPnP exposure of the web interface where not required.

Detection

  • Monitor HTTP requests for cgi-bin/DownloadCfg/RouterCfm.cfg, especially with an admin:language=pt cookie.
  • Alert on config file downloads from router management interfaces by unexpected source IPs.
  • Review router logs for authentication bypass patterns or anomalous admin sessions following config retrieval.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-14942 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

6.5CVE-2019-19516Intelbras wrn 150 firmware cross-site request forgery vulnerabilityIntelbras WRN 150 1.0.18 devices allow CSRF via GO=system_password.asp to the goform/SysToolChangePwd URI to change a password.EPSS 9.6%6.1CVE-2019-17222Intelbras wrn 150 firmware cross-site scripting vulnerabilityAn issue was discovered on Intelbras WRN 150 1.0.17 devices. There is stored XSS in the Service Name tab of the WAN configuration screen, leading to …EPSS 0.69%7.5CVE-2025-11371Gladinet CentreStack and Triofox unauthenticated local file inclusionCentreStack and Triofox in default installation and configuration contain an unauthenticated local file inclusion flaw that allows unintended disclos…KEVEPSS 92%analysed4.0CVE-2025-48928TeleMessage TM SGNL JSP heap dump exposes passwords sent over HTTPThe TeleMessage service through 2025-05-05 runs a JSP application whose heap content is roughly equivalent to a core dump, and a password previously …KEVEPSS 0.55%analysed7.5CVE-2020-17519Apache Flink JobManager REST interface arbitrary file readA change introduced in Apache Flink 1.11.0 lets attackers read any file on the JobManager's local filesystem through its REST interface, limited to f…KEVEPSS 98%analysed7.8CVE-2017-16651Roundcube Webmail file disclosure via attachment pluginRoundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows an authenticated user to read arbitrary files on the host filesyst…KEVEPSS 46%analysed5.5CVE-2016-3715ImageMagick EPHEMERAL coder allows arbitrary file deletionThe EPHEMERAL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 lets a crafted image cause deletion of arbitrary files. This is part of the…KEVEPSS 75%analysed

Source: NIST National Vulnerability Database (record CVE-2017-14942), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.