Intelbras
intelbras
50 CVEs • 48 products
Products (48)
Click to collapseToggle
Products (48)
Click to collapse
CVEs (50)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Intelbras 1Wifiber 120ac Inmesh Firmware Jun 17, 2026 Dec 25, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 Intelbras WiFiber 120AC inMesh before 1-1-220826 allows command injection by authenticated users, as demonstrated by the /boaform/formPing6 and /boaform/formTracert URIs for ping and traceroute. |
1Intelbras 2Sg 2404 Mr Firmware Sg 2404 Poe FirmwareJun 17, 2026 Nov 18, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 INTELBRAS SG 2404 MR 20180928-rel64938 allows authenticated attackers to arbitrarily create Administrator accounts via crafted user cookies. |
Authenticated stored cross-site scripting (XSS) vulnerability in "Field Server Address" field in INTELBRAS ATA 200 Firmware 74.19.10.21 allows attackers to inject JavaScript code through a crafted payload. |
Intelbras Router RF 301K Firmware 1.1.2 is vulnerable to Cross Site Request Forgery (CSRF) due to lack of security mechanisms for token protection and unsafe inputs and modules. |
Intelbras Router RF 301K Firmware 1.1.2 is vulnerable to Cross Site Request Forgery (CSRF) due to lack of validation and insecure configurations in inputs and modules. |
1Intelbras 2Win 300 Firmware Wrn 342 FirmwareJun 17, 2026 Apr 14, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The web interface on Intelbras WIN 300 and WRN 342 devices through 2021-01-04 allows remote attackers to discover credentials by reading the def_wirelesspassword line in the HTML source code. |
1Intelbras 2Tip200 Firmware Tip200lite FirmwareJul 9, 2026 Apr 12, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 INTELBRAS TELEFONE IP TIP200 version 60.61.75.22 allows an attacker to obtain sensitive information through /cgi-bin/cgiServer.exx. |
1Intelbras 3Tip200 Firmware Tip200lite FirmwareTip300 FirmwareJun 17, 2026 Nov 27, 2020 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Intelbras TIP200 60.61.75.15, TIP200LITE 60.61.75.15, and TIP300 65.61.75.15 devices allow /cgi-bin/cgiServer.exx?page= XSS. |
1Intelbras 3Tip200 Firmware Tip200lite FirmwareTip300 FirmwareJun 17, 2026 Nov 26, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Intelbras TIP 200 60.61.75.15, TIP 200 LITE 60.61.75.15, and TIP 300 65.61.75.22 devices allow cgi-bin/cgiServer.exx?page=../ Directory Traversal. |
CSRF on Intelbras CIP 92200 devices allows an attacker to access the panel and perform scraping or other analysis. |
1Intelbras 1Action Rf 1200 Firmware Jun 17, 2026 May 5, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Intelbras RF1200 1.1.3 devices allow CSRF to bypass the login.html form, as demonstrated by launching a scrapy process. |
Intelbras WRN240 devices do not require authentication to replace the firmware via a POST request to the incoming/Firmware.cfg URI. |
An issue was discovered on Intelbras IWR 3000N 1.8.7 devices. When the administrator password is changed from a certain client IP address, administrative authorization remains available to any client at that IP address,...Show more |
An issue was discovered on Intelbras IWR 3000N 1.8.7 devices. A malformed login request allows remote attackers to cause a denial of service (reboot), as demonstrated by JSON misparsing of the \""} string to v1/system/lo...Show more |
A CSRF issue was discovered on Intelbras IWR 3000N 1.8.7 devices, leading to complete control of the router, as demonstrated by v1/system/user. |
Intelbras IWR 3000N 1.8.7 devices allow disclosure of the administrator login name and password because v1/system/user is mishandled, a related issue to CVE-2019-17600. |
Intelbras WRN 150 1.0.18 devices allow CSRF via GO=system_password.asp to the goform/SysToolChangePwd URI to change a password. |
An issue was discovered on Intelbras WRN 150 1.0.17 devices. There is stored XSS in the Service Name tab of the WAN configuration screen, leading to a denial of service (inability to change the configuration). |
1Intelbras 1Iwr 1000n Firmware Jun 17, 2026 Oct 15, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Intelbras IWR 1000N 1.6.4 devices allow disclosure of the administrator login name and password because v1/system/user is mishandled. |
A CSRF issue was discovered on Intelbras IWR 3000N 1.5.0 devices, leading to complete control of the router, as demonstrated by v1/system/user. |