{"id":"CVE-2025-55976","details":"Intelbras IWR 3000N 1.9.8 exposes the Wi-Fi password in plaintext via the /api/wireless endpoint. Any unauthenticated user on the local network can directly obtain the Wi-Fi network password by querying this endpoint.","modified":"2026-05-04T08:47:18.736047Z","published":"2025-09-10T18:15:33.960Z","withdrawn":"2026-05-04T08:47:18.736047Z","references":[{"type":"WEB","url":"https://www.intelbras.com/pt-br/produto/roteador-wireless-n-300mbps-iwr-3000n"},{"type":"EVIDENCE","url":"https://medium.com/@windsormoreira/intelbras-iwr-3000n-unauthenticated-wi-fi-password-disclosure-cve-2025-55976-7cdac7770413"}],"affected":[{"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-55976.json","unresolved_ranges":[{"events":[{"introduced":"0"},{"last_affected":"1.9.8"}]}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}