Vulnerability Description
Intelbras IWR 3000N 1.9.8 exposes the Wi-Fi password in plaintext via the /api/wireless endpoint. Any unauthenticated user on the local network can directly obtain the Wi-Fi network password by querying this endpoint.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Intelbras | Iwr 3000N Firmware | <= 1.9.8 |
| Intelbras | Iwr 3000N | - |
Related Weaknesses (CWE)
References
- https://medium.com/@windsormoreira/intelbras-iwr-3000n-unauthenticated-wi-fi-pasExploitThird Party Advisory
- https://www.intelbras.com/pt-br/produto/roteador-wireless-n-300mbps-iwr-3000nBroken Link
FAQ
What is CVE-2025-55976?
CVE-2025-55976 is a vulnerability with a CVSS score of 8.4 (HIGH). Intelbras IWR 3000N 1.9.8 exposes the Wi-Fi password in plaintext via the /api/wireless endpoint. Any unauthenticated user on the local network can directly obtain the Wi-Fi network password by queryi...
How severe is CVE-2025-55976?
CVE-2025-55976 has been rated HIGH with a CVSS base score of 8.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-55976?
Check the references section above for vendor advisories and patch information. Affected products include: Intelbras Iwr 3000N Firmware, Intelbras Iwr 3000N.