CVE-2021-3017
About
The web interface on Intelbras WIN 300 and WRN 342 devices through 2021-01-04 allows remote attackers to discover credentials by reading the def_wirelesspassword line in the HTML source code.
Rainforest analyst review
This is embarrassingly simple: on these Intelbras routers, the Wi-Fi password sits in plaintext in the web interface's HTML source, in a variable called def_wirelesspassword. Anyone who can reach the admin page and hit View Source reads the wireless credential directly — no exploit, no tooling, just the browser. The scope is limited to confidentiality (the password), but for a home or small-office router that credential is the whole perimeter.
The practical urgency depends entirely on who can reach that web interface. If the management page is only on the LAN, an attacker already needs a foothold on the network to read a password protecting that same network — modest value. The danger spikes if remote management is enabled and the interface faces the internet, because then the wireless key is effectively public to any scanner that fingerprints these devices. Consumer routers are notorious for shipping remote admin on or getting exposed by accident.
For us the entire decision is reachability. We'd inventory any Intelbras WIN 300 or WRN 342 in the estate and check one thing: is the web interface exposed beyond the local segment? An internet-facing one is a live credential leak and gets pulled or firewalled now; a LAN-only one is a hygiene item. There's no version ceiling to chase here — the data cites devices through 2021-01-04 — so mitigation is exposure control, not patching.
References
Related CVEs
No related CVEs.
Frequently asked questions
What is CVE-2021-3017?
The web interface on Intelbras WIN 300 and WRN 342 devices through 2021-01-04 allows remote attackers to discover credentials by reading the def_wirelesspassword line in the HTML source code.
How severe is CVE-2021-3017?
CVE-2021-3017 carries a CVSS 3.1 base score of 7.5, rated high. On the Rainforest Risk Index — which weighs the severity alongside how easy the flaw is to reach and how broad its impact is — it scores 75 out of 100, in the high band.
How is CVE-2021-3017 exploited?
According to the CVSS vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N): attack vector Network, attack complexity Low, privileges required None, user interaction None. Impact on confidentiality High, integrity None and availability None.
Which products are affected by CVE-2021-3017?
Public advisories list the following as affected: win 300, win 300 firmware, wrn 342, wrn 342 firmware. Check the references on this page for the exact versions each vendor confirms.
How do I fix CVE-2021-3017?
Apply the fix the vendor published — the references on this page link to the primary advisories and patches. When patching can't happen right away, reduce the exposure of the affected component and watch it for exploitation attempts. Rainforest customers see this vulnerability correlated to their own assets and prioritized by real exposure, not by score alone.
Empower Your Security Strategy with Rainforest
Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.
