CVE-2025-55976: Intelbras Iwr 3000n Firmware

High severity, CVSS 8.4. EPSS: 3.3% chance of exploitation in the next 30 days.

Intelbras IWR 3000N 1.9.8 exposes the Wi-Fi password in plaintext via the /api/wireless endpoint. Any unauthenticated user on the local network can directly obtain the Wi-Fi network password by querying this endpoint.

Affected products

  • Intelbras Iwr 3000n Firmware: up to and including 1.9.8

Published 2025-09-10. Last modified 2026-06-17.