← Vulnerability feed

Vulnerability record · CVE-2021-3017 · published 14 April 2021

CVE-2021-3017: Intelbras router web interface exposes credentials in HTML source

Intelbras · Win 300 Firmware

The web interface on Intelbras WIN 300 and WRN 342 devices through 2021-01-04 embeds the wireless password in the page source via the def_wirelesspassword line. Anyone who can load the interface can read the credential directly, so the device's Wi-Fi secret is effectively public to anyone with network reach to the management page.

7.5 CVSS 3.1 High EPSS 63% · top 0.8%
7.5CVSS 3.1 base score, v2 5.0
63%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

The web interface on Intelbras WIN 300 and WRN 342 devices through 2021-01-04 allows remote attackers to discover credentials by reading the def_wirelesspassword line in the HTML source code.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityThe credential leak is remotely reachable without authentication and carries a high EPSS score, though it is not in KEV and grants only network access rather than device control.

What it is

The web interface on Intelbras WIN 300 and WRN 342 devices through 2021-01-04 embeds the wireless password in the page source via the def_wirelesspassword line. Anyone who can load the interface can read the credential directly, so the device's Wi-Fi secret is effectively public to anyone with network reach to the management page.

Impact

An attacker obtains the plaintext wireless password, enabling unauthorized access to the Wi-Fi network and any resources reachable through it. The flaw is confidentiality-only; no code execution or configuration change is granted by the leak itself.

Attack surface

Reachable over the network through the device web interface with no authentication and no user interaction, per the CVSS vector AV:N/AC:L/PR:N/UI:N. The description does not state whether the interface is limited to the LAN side, so exposure depends on how the device is deployed.

Exploitation

Not listed in CISA KEV and no public exploit tag appears in the references, but EPSS is 0.63023 (99.2nd percentile), indicating a high modeled likelihood of exploitation activity. Reference tags are only Third Party Advisory and Vendor Advisory, so no confirmed in-the-wild exploitation is documented in this record.

What to do

  • Apply the vendor firmware update or guidance from the Intelbras advisory for WIN 300 and WRN 342; if no fix exists, replace or retire the affected devices.
  • Do not expose the router web interface to the internet; restrict management access to trusted LAN hosts only.
  • Change the wireless password and any reused administrative credentials, since the value was readable in page source.
  • Disable remote management and UPnP-style WAN access on these routers where the option exists.
  • Segment or monitor the network for unauthorized clients that may have joined using the leaked key.

Detection

  • Search HTTP response bodies from router management pages for the string def_wirelesspassword to identify exposed devices.
  • Monitor for external or unexpected hosts requesting the router web interface, especially from WAN-side addresses.
  • Review wireless association logs for new or unknown clients joining after exposure.
  • Inventory network devices for Intelbras WIN 300 and WRN 342 models and flag any with internet-facing management interfaces.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-3017 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Source: NIST National Vulnerability Database (record CVE-2021-3017), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.