vendor:
Wireless N 150Mbps WRN240
by:
Elber Tavares
7.5
CVSS
HIGH
Authentication Bypass
287
CWE
Product Name: Wireless N 150Mbps WRN240
Affected Version From: Intelbras Wireless N 150Mbps - WRN240
Affected Version To: Intelbras Wireless N 150Mbps - WRN240
Patch Exists: YES
Related CWE: CVE-2019-19142
CPE: h:intelbras:wireless_n_150mbps_wrn240
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: linux, windows
2019
Intelbras Wireless N 150Mbps WRN240 – Authentication Bypass (Config Upload)
Intelbras WRN240 devices do not require authentication to replace the firmware via a POST request to the incoming/Firmware.cfg URI.
Mitigation:
Ensure that authentication is required for firmware updates.