Search

Find a vulnerability

Search criteria

    38 vulnerabilities by intelbras

    CVE-2026-101265 (GCVE-0-2026-101265)

    Vulnerability from nvd – Published: 2026-09-28 23:30 – Updated: 2026-09-29 12:08
    VLAI
    Title
    Intelbras TIP 125i Básico sensitive information in source
    Summary
    A vulnerability was identified in Intelbras TIP 125i 4.3.35/4.3.41. The affected element is an unknown function of the component Básico Page. Such manipulation leads to inclusion of sensitive information in source code. The attack can be launched remotely. A high complexity level is associated with this attack. The exploitability is described as difficult. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-29 12:07 UTC
    CWE
    • CWE-540 - Inclusion of Sensitive Information in Source Code
    • CWE-200 - Information Disclosure
    References
    URL Tags
    https://vuldb.com/vuln/411033 vdb-entry
    https://vuldb.com/vuln/411033/cti signaturepermissions-required
    https://vuldb.com/cve/CVE-2026-101265 third-party-advisory
    https://vuldb.com/submit/916125 third-party-advisory
    Impacted products
    Vendor Product Version
    Intelbras TIP 125i Affected: 4.3.35
    Affected: 4.3.41
        cpe:2.3:h:intelbras:tip_125i:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-101265",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-29T12:07:58.106106Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-29T12:08:26.960Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://vuldb.com/submit/916125"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:h:intelbras:tip_125i:*:*:*:*:*:*:*:*"
              ],
              "modules": [
                "B\u00e1sico Page"
              ],
              "product": "TIP 125i",
              "vendor": "Intelbras",
              "versions": [
                {
                  "status": "affected",
                  "version": "4.3.35"
                },
                {
                  "status": "affected",
                  "version": "4.3.41"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "TheL4zyF0x (VulDB User)"
            },
            {
              "lang": "en",
              "type": "coordinator",
              "value": "VulDB CNA Team"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A vulnerability was identified in Intelbras TIP 125i 4.3.35/4.3.41. The affected element is an unknown function of the component B\u00e1sico Page. Such manipulation leads to inclusion of sensitive information in source code. The attack can be launched remotely. A high complexity level is associated with this attack. The exploitability is described as difficult. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 2.3,
                "baseSeverity": "LOW",
                "vectorString": "CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P",
                "version": "4.0"
              }
            },
            {
              "cvssV3_1": {
                "baseScore": 3.1,
                "baseSeverity": "LOW",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R",
                "version": "3.1"
              }
            },
            {
              "cvssV3_0": {
                "baseScore": 3.1,
                "baseSeverity": "LOW",
                "vectorString": "CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R",
                "version": "3.0"
              }
            },
            {
              "cvssV2_0": {
                "baseScore": 2.1,
                "vectorString": "AV:N/AC:H/Au:S/C:P/I:N/A:N/E:POC/RL:ND/RC:UR",
                "version": "2.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-540",
                  "description": "Inclusion of Sensitive Information in Source Code",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-200",
                  "description": "Information Disclosure",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-28T23:30:10.163Z",
            "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
            "shortName": "VulDB"
          },
          "references": [
            {
              "name": "VDB-411033 | Intelbras TIP 125i B\u00e1sico sensitive information in source",
              "tags": [
                "vdb-entry"
              ],
              "url": "https://vuldb.com/vuln/411033"
            },
            {
              "name": "VDB-411033 | CTI Indicators (IOB, IOC, TTP)",
              "tags": [
                "signature",
                "permissions-required"
              ],
              "url": "https://vuldb.com/vuln/411033/cti"
            },
            {
              "name": "CVE-2026-101265 | CVE Analysis and Report",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/cve/CVE-2026-101265"
            },
            {
              "name": "Submit #916125 | Intelbras Intelbras TIP125_I 4.3.35/4.3.41 Sensitive Data Exposure",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/submit/916125"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-09-28T00:00:00.000Z",
              "value": "Advisory disclosed"
            },
            {
              "lang": "en",
              "time": "2026-09-28T02:00:00.000Z",
              "value": "VulDB entry created"
            },
            {
              "lang": "en",
              "time": "2026-09-28T13:46:12.000Z",
              "value": "VulDB entry last update"
            }
          ],
          "title": "Intelbras TIP 125i B\u00e1sico sensitive information in source",
          "x_generator": [
            "VulDB PVTS v202609"
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "assignerShortName": "VulDB",
        "cveId": "CVE-2026-101265",
        "datePublished": "2026-09-28T23:30:10.163Z",
        "dateReserved": "2026-09-28T11:41:07.968Z",
        "dateUpdated": "2026-09-29T12:08:26.960Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-12211 (GCVE-0-2026-12211)

    Vulnerability from nvd – Published: 2026-06-15 02:45 – Updated: 2026-06-15 10:34
    VLAI
    Title
    Intelbras iNVU 7016 FT Web syslog path traversal
    Summary
    A flaw has been found in Intelbras iNVU 7016 FT 3.004.00IB000.0.T Build 2025-09-26. This impacts an unknown function of the file /RPC2_Loadfile/syslog/ of the component Web Interface. Executing a manipulation can lead to path traversal. The attack can be launched remotely. The exploit has been published and may be used. It is recommended to upgrade the affected component. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-06-15 10:34 UTC
    CWE
    Impacted products
    Vendor Product Version
    Intelbras iNVU 7016 FT Affected: 3.004.00IB000.0.T Build 2025-09-26
        cpe:2.3:h:intelbras:invu_7016_ft:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-12211",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-06-15T10:34:27.235437Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-06-15T10:34:51.316Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:h:intelbras:invu_7016_ft:*:*:*:*:*:*:*:*"
              ],
              "modules": [
                "Web Interface"
              ],
              "product": "iNVU 7016 FT",
              "vendor": "Intelbras",
              "versions": [
                {
                  "status": "affected",
                  "version": "3.004.00IB000.0.T Build 2025-09-26"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "coaglio (VulDB User)"
            },
            {
              "lang": "en",
              "type": "coordinator",
              "value": "VulDB CNA Team"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A flaw has been found in Intelbras iNVU 7016 FT 3.004.00IB000.0.T Build 2025-09-26. This impacts an unknown function of the file /RPC2_Loadfile/syslog/ of the component Web Interface. Executing a manipulation can lead to path traversal. The attack can be launched remotely. The exploit has been published and may be used. It is recommended to upgrade the affected component. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 5.1,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P",
                "version": "4.0"
              }
            },
            {
              "cvssV3_1": {
                "baseScore": 2.7,
                "baseSeverity": "LOW",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C",
                "version": "3.1"
              }
            },
            {
              "cvssV3_0": {
                "baseScore": 2.7,
                "baseSeverity": "LOW",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C",
                "version": "3.0"
              }
            },
            {
              "cvssV2_0": {
                "baseScore": 3.3,
                "vectorString": "AV:N/AC:L/Au:M/C:P/I:N/A:N/E:POC/RL:OF/RC:C",
                "version": "2.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-22",
                  "description": "Path Traversal",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-06-15T02:45:08.782Z",
            "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
            "shortName": "VulDB"
          },
          "references": [
            {
              "name": "VDB-370853 | Intelbras iNVU 7016 FT Web syslog path traversal",
              "tags": [
                "vdb-entry"
              ],
              "url": "https://vuldb.com/vuln/370853"
            },
            {
              "name": "VDB-370853 | CTI Indicators (IOB, IOC, TTP, IOA)",
              "tags": [
                "signature",
                "permissions-required"
              ],
              "url": "https://vuldb.com/vuln/370853/cti"
            },
            {
              "name": "CVE-2026-12211 | CVE Analysis and Report",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/cve/CVE-2026-12211"
            },
            {
              "name": "Submit #832544 | Intelbras iNVU 7016 FT 3.004.00IB000.0.T (Build 2025-09-26) Path Traversal",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/submit/832544"
            },
            {
              "tags": [
                "exploit"
              ],
              "url": "https://coaglio.com/writeups/lfi-intelbras-invu.html"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "http://api-cronos.intelbras.com.br/download/INVU/INVU7016FT/prod/INVU7016FT-2026.05.29-712953bf2bb2af7e72d0577ad5ef6455.260527.BIN"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-06-14T00:00:00.000Z",
              "value": "Advisory disclosed"
            },
            {
              "lang": "en",
              "time": "2026-06-14T02:00:00.000Z",
              "value": "VulDB entry created"
            },
            {
              "lang": "en",
              "time": "2026-06-14T14:38:47.000Z",
              "value": "VulDB entry last update"
            }
          ],
          "title": "Intelbras iNVU 7016 FT Web syslog path traversal"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "assignerShortName": "VulDB",
        "cveId": "CVE-2026-12211",
        "datePublished": "2026-06-15T02:45:08.782Z",
        "dateReserved": "2026-06-14T12:32:49.466Z",
        "dateUpdated": "2026-06-15T10:34:51.316Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2019-25472 (GCVE-0-2019-25472)

    Vulnerability from nvd – Published: 2026-03-11 18:23 – Updated: 2026-04-07 14:04
    VLAI
    Title
    IntelBras Telefone IP TIP200/200 LITE Arbitrary File Read via dumpConfigFile
    Summary
    IntelBras Telefone IP TIP200 and 200 LITE contain an unauthenticated arbitrary file read vulnerability in the dumpConfigFile function accessible via the cgiServer.exx endpoint. Attackers can send GET requests to /cgi-bin/cgiServer.exx with the command parameter containing dumpConfigFile() to read sensitive files including /etc/shadow and configuration files without proper authorization.
    SSVC
    Exploitation: poc Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-03-11 18:46 UTC
    CWE
    • CWE-73 - External Control of File Name or Path
    Date Public
    2019-09-02 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2019-25472",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-03-11T18:46:47.213472Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-03-11T19:31:02.474Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Telefone IP TIP 200",
              "vendor": "Intelbras",
              "versions": [
                {
                  "status": "affected",
                  "version": "*"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Telefone IP TIP 200 LITE",
              "vendor": "Intelbras",
              "versions": [
                {
                  "status": "affected",
                  "version": "*"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Todor Donev"
            }
          ],
          "datePublic": "2019-09-02T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eIntelBras Telefone IP TIP200 and 200 LITE contain an unauthenticated arbitrary file read vulnerability in the dumpConfigFile function accessible via the cgiServer.exx endpoint. Attackers can send GET requests to /cgi-bin/cgiServer.exx with the command parameter containing dumpConfigFile() to read sensitive files including /etc/shadow and configuration files without proper authorization.\u003c/p\u003e"
                }
              ],
              "value": "IntelBras Telefone IP TIP200 and 200 LITE contain an unauthenticated arbitrary file read vulnerability in the dumpConfigFile function accessible via the cgiServer.exx endpoint. Attackers can send GET requests to /cgi-bin/cgiServer.exx with the command parameter containing dumpConfigFile() to read sensitive files including /etc/shadow and configuration files without proper authorization."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.7,
                "baseSeverity": "HIGH",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "NONE",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-73",
                  "description": "CWE-73 External Control of File Name or Path",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-04-07T14:04:29.982Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "ExploitDB-47337",
              "tags": [
                "exploit"
              ],
              "url": "https://www.exploit-db.com/exploits/47337"
            },
            {
              "name": "Intelbras Product Documentation",
              "tags": [
                "product"
              ],
              "url": "https://backend.intelbras.com/sites/default/files/integration/lamina_tip-200-lite_e_tip-200.pdf"
            },
            {
              "name": "VulnCheck Advisory: IntelBras Telefone IP TIP200/200 LITE Arbitrary File Read via dumpConfigFile",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/intelbras-telefone-ip-tip200-200-lite-arbitrary-file-read-via-dumpconfigfile"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "IntelBras Telefone IP TIP200/200 LITE Arbitrary File Read via dumpConfigFile",
          "x_generator": {
            "engine": "vulncheck"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2019-25472",
        "datePublished": "2026-03-11T18:23:15.474Z",
        "dateReserved": "2026-02-22T14:43:03.387Z",
        "dateUpdated": "2026-04-07T14:04:29.982Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-2564 (GCVE-0-2026-2564)

    Vulnerability from nvd – Published: 2026-02-16 16:02 – Updated: 2026-02-23 10:12
    VLAI
    Title
    Intelbras VIP 3260 Z IA OutsideCmd password recovery
    Summary
    A security flaw has been discovered in Intelbras VIP 3260 Z IA 2.840.00IB005.0.T. Affected by this vulnerability is an unknown functionality of the file /OutsideCmd. The manipulation results in weak password recovery. It is possible to launch the attack remotely. Attacks of this nature are highly complex. The exploitation appears to be difficult. It is recommended to upgrade the affected component.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-02-17 14:54 UTC
    CWE
    References
    URL Tags
    https://vuldb.com/?id.346171 vdb-entry
    https://vuldb.com/?ctiid.346171 signaturepermissions-required
    https://vuldb.com/?submit.741776 third-party-advisory
    Impacted products
    Vendor Product Version
    Intelbras VIP 3260 Z IA Affected: 2.840.00IB005.0.T
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-2564",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-02-17T14:54:28.001175Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-02-17T14:54:37.992Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "VIP 3260 Z IA",
              "vendor": "Intelbras",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.840.00IB005.0.T"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "ak7r4 (VulDB User)"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A security flaw has been discovered in Intelbras VIP 3260 Z IA 2.840.00IB005.0.T. Affected by this vulnerability is an unknown functionality of the file /OutsideCmd. The manipulation results in weak password recovery. It is possible to launch the attack remotely. Attacks of this nature are highly complex. The exploitation appears to be difficult. It is recommended to upgrade the affected component."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 9.2,
                "baseSeverity": "CRITICAL",
                "vectorString": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X",
                "version": "4.0"
              }
            },
            {
              "cvssV3_1": {
                "baseScore": 8.1,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:X/RL:O/RC:C",
                "version": "3.1"
              }
            },
            {
              "cvssV3_0": {
                "baseScore": 8.1,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:X/RL:O/RC:C",
                "version": "3.0"
              }
            },
            {
              "cvssV2_0": {
                "baseScore": 7.6,
                "vectorString": "AV:N/AC:H/Au:N/C:C/I:C/A:C/E:ND/RL:OF/RC:C",
                "version": "2.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-640",
                  "description": "Weak Password Recovery",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-02-23T10:12:32.594Z",
            "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
            "shortName": "VulDB"
          },
          "references": [
            {
              "name": "VDB-346171 | Intelbras VIP 3260 Z IA OutsideCmd password recovery",
              "tags": [
                "vdb-entry"
              ],
              "url": "https://vuldb.com/?id.346171"
            },
            {
              "name": "VDB-346171 | CTI Indicators (IOB, IOC, TTP, IOA)",
              "tags": [
                "signature",
                "permissions-required"
              ],
              "url": "https://vuldb.com/?ctiid.346171"
            },
            {
              "name": "Submit #741776 | Intelbras VIP 3260 Z IA v2.840.00IB005.0.T Weak Password Recovery",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/?submit.741776"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-02-15T00:00:00.000Z",
              "value": "Advisory disclosed"
            },
            {
              "lang": "en",
              "time": "2026-02-15T01:00:00.000Z",
              "value": "VulDB entry created"
            },
            {
              "lang": "en",
              "time": "2026-02-18T15:38:32.000Z",
              "value": "VulDB entry last update"
            }
          ],
          "title": "Intelbras VIP 3260 Z IA OutsideCmd password recovery"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "assignerShortName": "VulDB",
        "cveId": "CVE-2026-2564",
        "datePublished": "2026-02-16T16:02:06.547Z",
        "dateReserved": "2026-02-15T19:22:27.386Z",
        "dateUpdated": "2026-02-23T10:12:32.594Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2020-36963 (GCVE-0-2020-36963)

    Vulnerability from nvd – Published: 2026-01-28 17:35 – Updated: 2026-07-28 01:47
    VLAI
    Title
    Intelbras Router RF 301K 1.1.2 - Authentication Bypass
    Summary
    Intelbras Router RF 301K firmware version 1.1.2 contains an authentication bypass vulnerability that allows unauthenticated attackers to download router configuration files. Attackers can send a specific HTTP GET request to /cgi-bin/DownloadCfg/RouterCfm.cfg to retrieve sensitive router configuration without authentication.
    SSVC
    Exploitation: poc Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-01-28 18:59 UTC
    CWE
    • CWE-306 - Missing Authentication for Critical Function
    Impacted products
    Vendor Product Version
    Intelbras Intelbras Router RF 301K Affected: firmware version 1.1.2
        cpe:2.3:h:intelbras:rf_301k:firmware:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2020-11-30 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2020-36963",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-01-28T18:59:41.650842Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-01-29T18:12:47.675Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://www.exploit-db.com/exploits/49126"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Intelbras Router RF 301K",
              "vendor": "Intelbras",
              "versions": [
                {
                  "status": "affected",
                  "version": "firmware version 1.1.2"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:h:intelbras:rf_301k:firmware:*:*:*:*:*:*:*",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Kaio Amaral"
            }
          ],
          "datePublic": "2020-11-30T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Intelbras Router RF 301K firmware version 1.1.2 contains an authentication bypass vulnerability that allows unauthenticated attackers to download router configuration files. Attackers can send a specific HTTP GET request to /cgi-bin/DownloadCfg/RouterCfm.cfg to retrieve sensitive router configuration without authentication."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.7,
                "baseSeverity": "HIGH",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "NONE",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-306",
                  "description": "Missing Authentication for Critical Function",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-07-28T01:47:05.787Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "ExploitDB-49126",
              "tags": [
                "exploit"
              ],
              "url": "https://www.exploit-db.com/exploits/49126"
            },
            {
              "name": "Intelbras Official Homepage",
              "tags": [
                "product"
              ],
              "url": "https://www.intelbras.com/pt-br/"
            },
            {
              "name": "VulnCheck Advisory: Intelbras Router RF 301K 1.1.2 - Authentication Bypass",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/intelbras-router-rf-k-authentication-bypass"
            }
          ],
          "title": "Intelbras Router RF 301K 1.1.2 - Authentication Bypass",
          "x_generator": {
            "engine": "vulncheck"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2020-36963",
        "datePublished": "2026-01-28T17:35:08.650Z",
        "dateReserved": "2026-01-27T15:47:07.998Z",
        "dateUpdated": "2026-07-28T01:47:05.787Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-13221 (GCVE-0-2025-13221)

    Vulnerability from nvd – Published: 2025-11-15 19:32 – Updated: 2026-01-07 16:53
    VLAI
    Title
    Intelbras UnniTI usuarios.xml credentials storage
    Summary
    A weakness has been identified in Intelbras UnniTI 24.07.11. The affected element is an unknown function of the file /xml/sistema/usuarios.xml. Executing manipulation of the argument Usuario/Senha can lead to unprotected storage of credentials. The attack can be executed remotely. The exploit has been made available to the public and could be exploited.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-01-07 16:53 UTC
    CWE
    • CWE-256 - Unprotected Storage of Credentials
    • CWE-255 - Credentials Management
    References
    URL Tags
    https://vuldb.com/?id.332537 vdb-entrytechnical-description
    https://vuldb.com/?ctiid.332537 signaturepermissions-required
    https://vuldb.com/?submit.685825 third-party-advisory
    https://www.notion.so/eldruin/Intelbras-UnniTI-Pl… exploit
    Impacted products
    Vendor Product Version
    Intelbras UnniTI Affected: 24.07.11
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-13221",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-01-07T16:53:06.187300Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-01-07T16:53:16.059Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "UnniTI",
              "vendor": "Intelbras",
              "versions": [
                {
                  "status": "affected",
                  "version": "24.07.11"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "eldruin (VulDB User)"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A weakness has been identified in Intelbras UnniTI 24.07.11. The affected element is an unknown function of the file /xml/sistema/usuarios.xml. Executing manipulation of the argument Usuario/Senha can lead to unprotected storage of credentials. The attack can be executed remotely. The exploit has been made available to the public and could be exploited."
            },
            {
              "lang": "de",
              "value": "Es wurde eine Schwachstelle in Intelbras UnniTI 24.07.11 entdeckt. Davon betroffen ist unbekannter Code der Datei /xml/sistema/usuarios.xml. Durch das Beeinflussen des Arguments Usuario/Senha mit unbekannten Daten kann eine unprotected storage of credentials-Schwachstelle ausgenutzt werden. Die Umsetzung des Angriffs kann dabei \u00fcber das Netzwerk erfolgen. Die Schwachstelle wurde \u00f6ffentlich offengelegt und k\u00f6nnte ausgenutzt werden."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 6.9,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P",
                "version": "4.0"
              }
            },
            {
              "cvssV3_1": {
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:W/RC:R",
                "version": "3.1"
              }
            },
            {
              "cvssV3_0": {
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:W/RC:R",
                "version": "3.0"
              }
            },
            {
              "cvssV2_0": {
                "baseScore": 5,
                "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N/E:POC/RL:W/RC:UR",
                "version": "2.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-256",
                  "description": "Unprotected Storage of Credentials",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-255",
                  "description": "Credentials Management",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-11-15T19:32:05.663Z",
            "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
            "shortName": "VulDB"
          },
          "references": [
            {
              "name": "VDB-332537 | Intelbras UnniTI usuarios.xml credentials storage",
              "tags": [
                "vdb-entry",
                "technical-description"
              ],
              "url": "https://vuldb.com/?id.332537"
            },
            {
              "name": "VDB-332537 | CTI Indicators (IOB, IOC, TTP, IOA)",
              "tags": [
                "signature",
                "permissions-required"
              ],
              "url": "https://vuldb.com/?ctiid.332537"
            },
            {
              "name": "Submit #685825 | Intelbras UnniTI 24.07.11 Unprotected Storage of Credentials",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/?submit.685825"
            },
            {
              "tags": [
                "exploit"
              ],
              "url": "https://www.notion.so/eldruin/Intelbras-UnniTI-Plaintext-Admin-Credentials-Disclosure-29c27474cccb8008b2d7ea60affdf86e?source=copy_link"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2025-11-14T00:00:00.000Z",
              "value": "Advisory disclosed"
            },
            {
              "lang": "en",
              "time": "2025-11-14T01:00:00.000Z",
              "value": "VulDB entry created"
            },
            {
              "lang": "en",
              "time": "2025-11-14T22:19:55.000Z",
              "value": "VulDB entry last update"
            }
          ],
          "title": "Intelbras UnniTI usuarios.xml credentials storage"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "assignerShortName": "VulDB",
        "cveId": "CVE-2025-13221",
        "datePublished": "2025-11-15T19:32:05.663Z",
        "dateReserved": "2025-11-14T21:14:33.763Z",
        "dateUpdated": "2026-01-07T16:53:16.059Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-8515 (GCVE-0-2025-8515)

    Vulnerability from nvd – Published: 2025-08-04 10:32 – Updated: 2025-10-29 06:53
    VLAI
    Title
    Intelbras InControl JSON Endpoint operador information disclosure
    Summary
    A weakness has been identified in Intelbras InControl 2.21.60.9. This vulnerability affects unknown code of the file /v1/operador/ of the component JSON Endpoint. Executing manipulation can lead to information disclosure. It is possible to launch the attack remotely. A high complexity level is associated with this attack. It is stated that the exploitability is difficult. The exploit has been made available to the public and could be exploited. Upgrading the affected component is advised.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-08-04 14:30 UTC
    CWE
    References
    URL Tags
    https://vuldb.com/?id.318641 vdb-entrytechnical-description
    https://vuldb.com/?ctiid.318641 signaturepermissions-required
    https://vuldb.com/?submit.579544 third-party-advisory
    https://backend.intelbras.com/sites/default/files… related
    Impacted products
    Vendor Product Version
    Intelbras InControl Affected: 2.21.60.9
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-8515",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-08-04T14:30:06.568840Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-08-04T15:00:05.698Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "modules": [
                "JSON Endpoint"
              ],
              "product": "InControl",
              "vendor": "Intelbras",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.21.60.9"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "lorenzomoulin (VulDB User)"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A weakness has been identified in Intelbras InControl 2.21.60.9. This vulnerability affects unknown code of the file /v1/operador/ of the component JSON Endpoint. Executing manipulation can lead to information disclosure. It is possible to launch the attack remotely. A high complexity level is associated with this attack. It is stated that the exploitability is difficult. The exploit has been made available to the public and could be exploited. Upgrading the affected component is advised."
            },
            {
              "lang": "de",
              "value": "Es wurde eine Schwachstelle in Intelbras InControl 2.21.60.9 entdeckt. Davon betroffen ist unbekannter Code der Datei /v1/operador/ der Komponente JSON Endpoint. Dank Manipulation mit unbekannten Daten kann eine information disclosure-Schwachstelle ausgenutzt werden. Die Umsetzung des Angriffs kann dabei \u00fcber das Netzwerk erfolgen. Ein Angriff erfordert eine vergleichsweise hohe Komplexit\u00e4t. Sie gilt als schwierig ausnutzbar. Der Exploit wurde der \u00d6ffentlichkeit bekannt gemacht und k\u00f6nnte verwendet werden. Es wird empfohlen, die betroffene Komponente zu aktualisieren."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 2.3,
                "baseSeverity": "LOW",
                "vectorString": "CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P",
                "version": "4.0"
              }
            },
            {
              "cvssV3_1": {
                "baseScore": 3.1,
                "baseSeverity": "LOW",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C",
                "version": "3.1"
              }
            },
            {
              "cvssV3_0": {
                "baseScore": 3.1,
                "baseSeverity": "LOW",
                "vectorString": "CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C",
                "version": "3.0"
              }
            },
            {
              "cvssV2_0": {
                "baseScore": 2.1,
                "vectorString": "AV:N/AC:H/Au:S/C:P/I:N/A:N/E:POC/RL:OF/RC:C",
                "version": "2.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-200",
                  "description": "Information Disclosure",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-284",
                  "description": "Improper Access Controls",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-10-29T06:53:04.612Z",
            "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
            "shortName": "VulDB"
          },
          "references": [
            {
              "name": "VDB-318641 | Intelbras InControl JSON Endpoint operador information disclosure",
              "tags": [
                "vdb-entry",
                "technical-description"
              ],
              "url": "https://vuldb.com/?id.318641"
            },
            {
              "name": "VDB-318641 | CTI Indicators (IOB, IOC, TTP, IOA)",
              "tags": [
                "signature",
                "permissions-required"
              ],
              "url": "https://vuldb.com/?ctiid.318641"
            },
            {
              "name": "Submit #579544 | Intelbras InControl  2.21.60.9 Information Disclosure",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/?submit.579544"
            },
            {
              "tags": [
                "related"
              ],
              "url": "https://backend.intelbras.com/sites/default/files/2025-08/Aviso%20de%20Seguran%C3%A7a%20-%20Incontrol%202.21.60%20e%202.21.61%20PT-IN%20.pdf"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2025-08-04T00:00:00.000Z",
              "value": "Advisory disclosed"
            },
            {
              "lang": "en",
              "time": "2025-08-04T02:00:00.000Z",
              "value": "VulDB entry created"
            },
            {
              "lang": "en",
              "time": "2025-10-29T07:57:56.000Z",
              "value": "VulDB entry last update"
            }
          ],
          "title": "Intelbras InControl JSON Endpoint operador information disclosure"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "assignerShortName": "VulDB",
        "cveId": "CVE-2025-8515",
        "datePublished": "2025-08-04T10:32:05.124Z",
        "dateReserved": "2025-08-04T05:41:27.160Z",
        "dateUpdated": "2025-10-29T06:53:04.612Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2025-7061 (GCVE-0-2025-7061)

    Vulnerability from nvd – Published: 2025-07-04 12:32 – Updated: 2025-07-07 16:23
    VLAI
    Title
    Intelbras InControl operador csv injection
    Summary
    A vulnerability was found in Intelbras InControl up to 2.21.60.9. It has been declared as problematic. This vulnerability affects unknown code of the file /v1/operador/. The manipulation leads to csv injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-07-07 16:23 UTC
    CWE
    References
    URL Tags
    https://vuldb.com/?id.314836 vdb-entry
    https://vuldb.com/?ctiid.314836 signaturepermissions-required
    https://vuldb.com/?submit.600881 third-party-advisory
    Impacted products
    Vendor Product Version
    Intelbras InControl Affected: 2.21.60.0
    Affected: 2.21.60.1
    Affected: 2.21.60.2
    Affected: 2.21.60.3
    Affected: 2.21.60.4
    Affected: 2.21.60.5
    Affected: 2.21.60.6
    Affected: 2.21.60.7
    Affected: 2.21.60.8
    Affected: 2.21.60.9
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-7061",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-07-07T16:23:15.540883Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-07-07T16:23:17.934Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://vuldb.com/?submit.600881"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "InControl",
              "vendor": "Intelbras",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.21.60.0"
                },
                {
                  "status": "affected",
                  "version": "2.21.60.1"
                },
                {
                  "status": "affected",
                  "version": "2.21.60.2"
                },
                {
                  "status": "affected",
                  "version": "2.21.60.3"
                },
                {
                  "status": "affected",
                  "version": "2.21.60.4"
                },
                {
                  "status": "affected",
                  "version": "2.21.60.5"
                },
                {
                  "status": "affected",
                  "version": "2.21.60.6"
                },
                {
                  "status": "affected",
                  "version": "2.21.60.7"
                },
                {
                  "status": "affected",
                  "version": "2.21.60.8"
                },
                {
                  "status": "affected",
                  "version": "2.21.60.9"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "lorenzomoulin (VulDB User)"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A vulnerability was found in Intelbras InControl up to 2.21.60.9. It has been declared as problematic. This vulnerability affects unknown code of the file /v1/operador/. The manipulation leads to csv injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way."
            },
            {
              "lang": "de",
              "value": "In Intelbras InControl bis 2.21.60.9 wurde eine Schwachstelle ausgemacht. Sie wurde als problematisch eingestuft. Das betrifft eine unbekannte Funktionalit\u00e4t der Datei /v1/operador/. Mittels dem Manipulieren mit unbekannten Daten kann eine csv injection-Schwachstelle ausgenutzt werden. Der Angriff kann \u00fcber das Netzwerk angegangen werden. Der Exploit steht zur \u00f6ffentlichen Verf\u00fcgung."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 5.1,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P",
                "version": "4.0"
              }
            },
            {
              "cvssV3_1": {
                "baseScore": 2.7,
                "baseSeverity": "LOW",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R",
                "version": "3.1"
              }
            },
            {
              "cvssV3_0": {
                "baseScore": 2.7,
                "baseSeverity": "LOW",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R",
                "version": "3.0"
              }
            },
            {
              "cvssV2_0": {
                "baseScore": 3.3,
                "vectorString": "AV:N/AC:L/Au:M/C:N/I:P/A:N/E:POC/RL:ND/RC:UR",
                "version": "2.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-1236",
                  "description": "CSV Injection",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-74",
                  "description": "Injection",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-07-04T12:32:04.865Z",
            "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
            "shortName": "VulDB"
          },
          "references": [
            {
              "name": "VDB-314836 | Intelbras InControl operador csv injection",
              "tags": [
                "vdb-entry"
              ],
              "url": "https://vuldb.com/?id.314836"
            },
            {
              "name": "VDB-314836 | CTI Indicators (IOB, IOC, IOA)",
              "tags": [
                "signature",
                "permissions-required"
              ],
              "url": "https://vuldb.com/?ctiid.314836"
            },
            {
              "name": "Submit #600881 | Intelbras InControl 2.21.60.9 CSV Injection",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/?submit.600881"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2025-07-04T00:00:00.000Z",
              "value": "Advisory disclosed"
            },
            {
              "lang": "en",
              "time": "2025-07-04T02:00:00.000Z",
              "value": "VulDB entry created"
            },
            {
              "lang": "en",
              "time": "2025-07-04T08:06:48.000Z",
              "value": "VulDB entry last update"
            }
          ],
          "title": "Intelbras InControl operador csv injection"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "assignerShortName": "VulDB",
        "cveId": "CVE-2025-7061",
        "datePublished": "2025-07-04T12:32:04.865Z",
        "dateReserved": "2025-07-04T06:01:33.147Z",
        "dateUpdated": "2025-07-07T16:23:17.934Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2025-6765 (GCVE-0-2025-6765)

    Vulnerability from nvd – Published: 2025-06-27 12:00 – Updated: 2025-06-27 13:00
    VLAI
    Title
    Intelbras InControl HTTP PUT Request operador permission
    Summary
    A vulnerability, which was classified as critical, has been found in Intelbras InControl 2.21.60.9. This issue affects some unknown processing of the file /v1/operador/ of the component HTTP PUT Request Handler. The manipulation leads to permission issues. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-06-27 12:59 UTC
    CWE
    • CWE-275 - Permission Issues
    • CWE-266 - Incorrect Privilege Assignment
    References
    URL Tags
    https://vuldb.com/?id.314075 vdb-entry
    https://vuldb.com/?ctiid.314075 signaturepermissions-required
    https://vuldb.com/?submit.599873 third-party-advisory
    https://vuldb.com/?submit.599880 third-party-advisory
    Impacted products
    Vendor Product Version
    Intelbras InControl Affected: 2.21.60.9
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-6765",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-06-27T12:59:57.761608Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-06-27T13:00:14.193Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://vuldb.com/?submit.599873"
              },
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://vuldb.com/?submit.599880"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "modules": [
                "HTTP PUT Request Handler"
              ],
              "product": "InControl",
              "vendor": "Intelbras",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.21.60.9"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "lorenzomoulin (VulDB User)"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A vulnerability, which was classified as critical, has been found in Intelbras InControl 2.21.60.9. This issue affects some unknown processing of the file /v1/operador/ of the component HTTP PUT Request Handler. The manipulation leads to permission issues. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way."
            },
            {
              "lang": "de",
              "value": "Eine Schwachstelle wurde in Intelbras InControl 2.21.60.9 entdeckt. Sie wurde als kritisch eingestuft. Davon betroffen ist unbekannter Code der Datei /v1/operador/ der Komponente HTTP PUT Request Handler. Durch die Manipulation mit unbekannten Daten kann eine permission issues-Schwachstelle ausgenutzt werden. Der Angriff kann \u00fcber das Netzwerk erfolgen. Der Exploit steht zur \u00f6ffentlichen Verf\u00fcgung."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
                "version": "4.0"
              }
            },
            {
              "cvssV3_1": {
                "baseScore": 6.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
                "version": "3.1"
              }
            },
            {
              "cvssV3_0": {
                "baseScore": 6.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
                "version": "3.0"
              }
            },
            {
              "cvssV2_0": {
                "baseScore": 6.5,
                "vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR",
                "version": "2.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-275",
                  "description": "Permission Issues",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-266",
                  "description": "Incorrect Privilege Assignment",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-06-27T12:00:15.432Z",
            "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
            "shortName": "VulDB"
          },
          "references": [
            {
              "name": "VDB-314075 | Intelbras InControl HTTP PUT Request operador permission",
              "tags": [
                "vdb-entry"
              ],
              "url": "https://vuldb.com/?id.314075"
            },
            {
              "name": "VDB-314075 | CTI Indicators (IOB, IOC, TTP, IOA)",
              "tags": [
                "signature",
                "permissions-required"
              ],
              "url": "https://vuldb.com/?ctiid.314075"
            },
            {
              "name": "Submit #599873 | Intelbras InControl 2.21.60.9 Improper Handling of Insufficient Permissions or Privileges",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/?submit.599873"
            },
            {
              "name": "Submit #599880 | Intelbras InControl  2.21.60.9 IDOR (Duplicate)",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/?submit.599880"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2025-06-27T00:00:00.000Z",
              "value": "Advisory disclosed"
            },
            {
              "lang": "en",
              "time": "2025-06-27T02:00:00.000Z",
              "value": "VulDB entry created"
            },
            {
              "lang": "en",
              "time": "2025-06-27T07:53:54.000Z",
              "value": "VulDB entry last update"
            }
          ],
          "title": "Intelbras InControl HTTP PUT Request operador permission"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "assignerShortName": "VulDB",
        "cveId": "CVE-2025-6765",
        "datePublished": "2025-06-27T12:00:15.432Z",
        "dateReserved": "2025-06-27T05:48:40.764Z",
        "dateUpdated": "2025-06-27T13:00:14.193Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2025-4996 (GCVE-0-2025-4996)

    Vulnerability from nvd – Published: 2025-05-20 19:00 – Updated: 2025-05-20 19:29
    VLAI
    Title
    Intelbras RF 301K Add Static IP cross site scripting
    Summary
    A vulnerability, which was classified as problematic, has been found in Intelbras RF 301K 1.1.5. This issue affects some unknown processing of the component Add Static IP. The manipulation of the argument Description leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-05-20 19:29 UTC
    CWE
    References
    URL Tags
    https://vuldb.com/?id.309647 vdb-entrytechnical-description
    https://vuldb.com/?ctiid.309647 signaturepermissions-required
    https://vuldb.com/?submit.501900 third-party-advisory
    Impacted products
    Vendor Product Version
    Intelbras RF 301K Affected: 1.1.5
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-4996",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-05-20T19:29:44.861317Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-05-20T19:29:56.525Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "modules": [
                "Add Static IP"
              ],
              "product": "RF 301K",
              "vendor": "Intelbras",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.1.5"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "Havook (VulDB User)"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A vulnerability, which was classified as problematic, has been found in Intelbras RF 301K 1.1.5. This issue affects some unknown processing of the component Add Static IP. The manipulation of the argument Description leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure."
            },
            {
              "lang": "de",
              "value": "Eine Schwachstelle wurde in Intelbras RF 301K 1.1.5 entdeckt. Sie wurde als problematisch eingestuft. Dies betrifft einen unbekannten Teil der Komponente Add Static IP. Durch Manipulieren des Arguments Description mit unbekannten Daten kann eine cross site scripting-Schwachstelle ausgenutzt werden. Der Angriff kann \u00fcber das Netzwerk passieren. Der Exploit steht zur \u00f6ffentlichen Verf\u00fcgung."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 4.8,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0"
              }
            },
            {
              "cvssV3_1": {
                "baseScore": 2.4,
                "baseSeverity": "LOW",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N",
                "version": "3.1"
              }
            },
            {
              "cvssV3_0": {
                "baseScore": 2.4,
                "baseSeverity": "LOW",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N",
                "version": "3.0"
              }
            },
            {
              "cvssV2_0": {
                "baseScore": 3.3,
                "vectorString": "AV:N/AC:L/Au:M/C:N/I:P/A:N",
                "version": "2.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-79",
                  "description": "Cross Site Scripting",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-94",
                  "description": "Code Injection",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-05-20T19:00:09.160Z",
            "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
            "shortName": "VulDB"
          },
          "references": [
            {
              "name": "VDB-309647 | Intelbras RF 301K Add Static IP cross site scripting",
              "tags": [
                "vdb-entry",
                "technical-description"
              ],
              "url": "https://vuldb.com/?id.309647"
            },
            {
              "name": "VDB-309647 | CTI Indicators (IOB, IOC, TTP, IOA)",
              "tags": [
                "signature",
                "permissions-required"
              ],
              "url": "https://vuldb.com/?ctiid.309647"
            },
            {
              "name": "Submit #501900 | INTELBRAS RF 301K 1.1.5 Cross Site Scripting",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/?submit.501900"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2025-05-20T00:00:00.000Z",
              "value": "Advisory disclosed"
            },
            {
              "lang": "en",
              "time": "2025-05-20T02:00:00.000Z",
              "value": "VulDB entry created"
            },
            {
              "lang": "en",
              "time": "2025-05-20T14:58:41.000Z",
              "value": "VulDB entry last update"
            }
          ],
          "title": "Intelbras RF 301K Add Static IP cross site scripting"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "assignerShortName": "VulDB",
        "cveId": "CVE-2025-4996",
        "datePublished": "2025-05-20T19:00:09.160Z",
        "dateReserved": "2025-05-20T12:53:31.524Z",
        "dateUpdated": "2025-05-20T19:29:56.525Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2025-4286 (GCVE-0-2025-4286)

    Vulnerability from nvd – Published: 2025-05-05 19:31 – Updated: 2025-05-05 20:05
    VLAI
    Title
    Intelbras InControl Dispositivos Edição Page credentials storage
    Summary
    A vulnerability was found in Intelbras InControl up to 2.21.59. It has been classified as problematic. Affected is an unknown function of the component Dispositivos Edição Page. The manipulation of the argument Senha de Comunicação leads to unprotected storage of credentials. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. According to the vendor this issue should be fixed in a later release.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-05-05 20:05 UTC
    CWE
    • CWE-256 - Unprotected Storage of Credentials
    • CWE-255 - Credentials Management
    References
    URL Tags
    https://vuldb.com/?id.307392 vdb-entrytechnical-description
    https://vuldb.com/?ctiid.307392 signaturepermissions-required
    https://vuldb.com/?submit.483834 third-party-advisory
    https://eldruin.notion.site/Intelbras-InControl-v… exploit
    Impacted products
    Vendor Product Version
    Intelbras InControl Affected: 2.21.0
    Affected: 2.21.1
    Affected: 2.21.2
    Affected: 2.21.3
    Affected: 2.21.4
    Affected: 2.21.5
    Affected: 2.21.6
    Affected: 2.21.7
    Affected: 2.21.8
    Affected: 2.21.9
    Affected: 2.21.10
    Affected: 2.21.11
    Affected: 2.21.12
    Affected: 2.21.13
    Affected: 2.21.14
    Affected: 2.21.15
    Affected: 2.21.16
    Affected: 2.21.17
    Affected: 2.21.18
    Affected: 2.21.19
    Affected: 2.21.20
    Affected: 2.21.21
    Affected: 2.21.22
    Affected: 2.21.23
    Affected: 2.21.24
    Affected: 2.21.25
    Affected: 2.21.26
    Affected: 2.21.27
    Affected: 2.21.28
    Affected: 2.21.29
    Affected: 2.21.30
    Affected: 2.21.31
    Affected: 2.21.32
    Affected: 2.21.33
    Affected: 2.21.34
    Affected: 2.21.35
    Affected: 2.21.36
    Affected: 2.21.37
    Affected: 2.21.38
    Affected: 2.21.39
    Affected: 2.21.40
    Affected: 2.21.41
    Affected: 2.21.42
    Affected: 2.21.43
    Affected: 2.21.44
    Affected: 2.21.45
    Affected: 2.21.46
    Affected: 2.21.47
    Affected: 2.21.48
    Affected: 2.21.49
    Affected: 2.21.50
    Affected: 2.21.51
    Affected: 2.21.52
    Affected: 2.21.53
    Affected: 2.21.54
    Affected: 2.21.55
    Affected: 2.21.56
    Affected: 2.21.57
    Affected: 2.21.58
    Affected: 2.21.59
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-4286",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-05-05T20:05:08.952078Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-05-05T20:05:12.475Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "modules": [
                "Dispositivos Edi\u00e7\u00e3o Page"
              ],
              "product": "InControl",
              "vendor": "Intelbras",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.21.0"
                },
                {
                  "status": "affected",
                  "version": "2.21.1"
                },
                {
                  "status": "affected",
                  "version": "2.21.2"
                },
                {
                  "status": "affected",
                  "version": "2.21.3"
                },
                {
                  "status": "affected",
                  "version": "2.21.4"
                },
                {
                  "status": "affected",
                  "version": "2.21.5"
                },
                {
                  "status": "affected",
                  "version": "2.21.6"
                },
                {
                  "status": "affected",
                  "version": "2.21.7"
                },
                {
                  "status": "affected",
                  "version": "2.21.8"
                },
                {
                  "status": "affected",
                  "version": "2.21.9"
                },
                {
                  "status": "affected",
                  "version": "2.21.10"
                },
                {
                  "status": "affected",
                  "version": "2.21.11"
                },
                {
                  "status": "affected",
                  "version": "2.21.12"
                },
                {
                  "status": "affected",
                  "version": "2.21.13"
                },
                {
                  "status": "affected",
                  "version": "2.21.14"
                },
                {
                  "status": "affected",
                  "version": "2.21.15"
                },
                {
                  "status": "affected",
                  "version": "2.21.16"
                },
                {
                  "status": "affected",
                  "version": "2.21.17"
                },
                {
                  "status": "affected",
                  "version": "2.21.18"
                },
                {
                  "status": "affected",
                  "version": "2.21.19"
                },
                {
                  "status": "affected",
                  "version": "2.21.20"
                },
                {
                  "status": "affected",
                  "version": "2.21.21"
                },
                {
                  "status": "affected",
                  "version": "2.21.22"
                },
                {
                  "status": "affected",
                  "version": "2.21.23"
                },
                {
                  "status": "affected",
                  "version": "2.21.24"
                },
                {
                  "status": "affected",
                  "version": "2.21.25"
                },
                {
                  "status": "affected",
                  "version": "2.21.26"
                },
                {
                  "status": "affected",
                  "version": "2.21.27"
                },
                {
                  "status": "affected",
                  "version": "2.21.28"
                },
                {
                  "status": "affected",
                  "version": "2.21.29"
                },
                {
                  "status": "affected",
                  "version": "2.21.30"
                },
                {
                  "status": "affected",
                  "version": "2.21.31"
                },
                {
                  "status": "affected",
                  "version": "2.21.32"
                },
                {
                  "status": "affected",
                  "version": "2.21.33"
                },
                {
                  "status": "affected",
                  "version": "2.21.34"
                },
                {
                  "status": "affected",
                  "version": "2.21.35"
                },
                {
                  "status": "affected",
                  "version": "2.21.36"
                },
                {
                  "status": "affected",
                  "version": "2.21.37"
                },
                {
                  "status": "affected",
                  "version": "2.21.38"
                },
                {
                  "status": "affected",
                  "version": "2.21.39"
                },
                {
                  "status": "affected",
                  "version": "2.21.40"
                },
                {
                  "status": "affected",
                  "version": "2.21.41"
                },
                {
                  "status": "affected",
                  "version": "2.21.42"
                },
                {
                  "status": "affected",
                  "version": "2.21.43"
                },
                {
                  "status": "affected",
                  "version": "2.21.44"
                },
                {
                  "status": "affected",
                  "version": "2.21.45"
                },
                {
                  "status": "affected",
                  "version": "2.21.46"
                },
                {
                  "status": "affected",
                  "version": "2.21.47"
                },
                {
                  "status": "affected",
                  "version": "2.21.48"
                },
                {
                  "status": "affected",
                  "version": "2.21.49"
                },
                {
                  "status": "affected",
                  "version": "2.21.50"
                },
                {
                  "status": "affected",
                  "version": "2.21.51"
                },
                {
                  "status": "affected",
                  "version": "2.21.52"
                },
                {
                  "status": "affected",
                  "version": "2.21.53"
                },
                {
                  "status": "affected",
                  "version": "2.21.54"
                },
                {
                  "status": "affected",
                  "version": "2.21.55"
                },
                {
                  "status": "affected",
                  "version": "2.21.56"
                },
                {
                  "status": "affected",
                  "version": "2.21.57"
                },
                {
                  "status": "affected",
                  "version": "2.21.58"
                },
                {
                  "status": "affected",
                  "version": "2.21.59"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "eldruin (VulDB User)"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A vulnerability was found in Intelbras InControl up to 2.21.59. It has been classified as problematic. Affected is an unknown function of the component Dispositivos Edi\u00e7\u00e3o Page. The manipulation of the argument Senha de Comunica\u00e7\u00e3o leads to unprotected storage of credentials. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. According to the vendor this issue should be fixed in a later release."
            },
            {
              "lang": "de",
              "value": "Es wurde eine problematische Schwachstelle in Intelbras InControl bis 2.21.59 ausgemacht. Es geht dabei um eine nicht klar definierte Funktion der Komponente Dispositivos Edi\u00e7\u00e3o Page. Durch Manipulieren des Arguments Senha de Comunica\u00e7\u00e3o mit unbekannten Daten kann eine unprotected storage of credentials-Schwachstelle ausgenutzt werden. Der Angriff kann \u00fcber das Netzwerk passieren. Der Exploit steht zur \u00f6ffentlichen Verf\u00fcgung."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 5.1,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0"
              }
            },
            {
              "cvssV3_1": {
                "baseScore": 2.7,
                "baseSeverity": "LOW",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N",
                "version": "3.1"
              }
            },
            {
              "cvssV3_0": {
                "baseScore": 2.7,
                "baseSeverity": "LOW",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N",
                "version": "3.0"
              }
            },
            {
              "cvssV2_0": {
                "baseScore": 3.3,
                "vectorString": "AV:N/AC:L/Au:M/C:P/I:N/A:N",
                "version": "2.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-256",
                  "description": "Unprotected Storage of Credentials",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-255",
                  "description": "Credentials Management",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-05-05T19:31:04.865Z",
            "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
            "shortName": "VulDB"
          },
          "references": [
            {
              "name": "VDB-307392 | Intelbras InControl Dispositivos Edi\u00e7\u00e3o Page credentials storage",
              "tags": [
                "vdb-entry",
                "technical-description"
              ],
              "url": "https://vuldb.com/?id.307392"
            },
            {
              "name": "VDB-307392 | CTI Indicators (IOB, IOC, TTP, IOA)",
              "tags": [
                "signature",
                "permissions-required"
              ],
              "url": "https://vuldb.com/?ctiid.307392"
            },
            {
              "name": "Submit #483834 | Intelbras InControl 2.21.57 Insecure Storage of Sensitive Information",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/?submit.483834"
            },
            {
              "tags": [
                "exploit"
              ],
              "url": "https://eldruin.notion.site/Intelbras-InControl-v2-21-57-Storing-password-in-insecure-format-17d27474cccb8003b647ea832186b162?pvs=4"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2025-05-05T00:00:00.000Z",
              "value": "Advisory disclosed"
            },
            {
              "lang": "en",
              "time": "2025-05-05T02:00:00.000Z",
              "value": "VulDB entry created"
            },
            {
              "lang": "en",
              "time": "2025-05-05T13:51:11.000Z",
              "value": "VulDB entry last update"
            }
          ],
          "title": "Intelbras InControl Dispositivos Edi\u00e7\u00e3o Page credentials storage"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "assignerShortName": "VulDB",
        "cveId": "CVE-2025-4286",
        "datePublished": "2025-05-05T19:31:04.865Z",
        "dateReserved": "2025-05-05T11:46:08.317Z",
        "dateUpdated": "2025-05-05T20:05:12.475Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2025-3157 (GCVE-0-2025-3157)

    Vulnerability from nvd – Published: 2025-04-03 13:31 – Updated: 2025-04-03 15:41
    VLAI
    Title
    Intelbras WRN 150 Wireless Menu cross site scripting
    Summary
    A vulnerability was found in Intelbras WRN 150 1.0.15_pt_ITB01. It has been rated as problematic. This issue affects some unknown processing of the component Wireless Menu. The manipulation of the argument SSID leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. It is recommended to upgrade the affected component. The vendor was contacted early about this issue and explains that the latest version is not affected.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-04-03 15:37 UTC
    CWE
    References
    URL Tags
    https://vuldb.com/?id.303101 vdb-entrytechnical-description
    https://vuldb.com/?ctiid.303101 signaturepermissions-required
    https://vuldb.com/?submit.501902 third-party-advisory
    Impacted products
    Vendor Product Version
    Intelbras WRN 150 Affected: 1.0.15_pt_ITB01
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-3157",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-04-03T15:37:37.202340Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-04-03T15:41:39.365Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "modules": [
                "Wireless Menu"
              ],
              "product": "WRN 150",
              "vendor": "Intelbras",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.0.15_pt_ITB01"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "Fergod (VulDB User)"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A vulnerability was found in Intelbras WRN 150 1.0.15_pt_ITB01. It has been rated as problematic. This issue affects some unknown processing of the component Wireless Menu. The manipulation of the argument SSID leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. It is recommended to upgrade the affected component. The vendor was contacted early about this issue and explains that the latest version is not affected."
            },
            {
              "lang": "de",
              "value": "Eine Schwachstelle wurde in Intelbras WRN 150 1.0.15_pt_ITB01 ausgemacht. Sie wurde als problematisch eingestuft. Es geht hierbei um eine nicht n\u00e4her spezifizierte Funktion der Komponente Wireless Menu. Durch das Manipulieren des Arguments SSID mit unbekannten Daten kann eine cross site scripting-Schwachstelle ausgenutzt werden. Der Angriff kann \u00fcber das Netzwerk angegangen werden. Der Exploit steht zur \u00f6ffentlichen Verf\u00fcgung. Als bestm\u00f6gliche Massnahme wird das Einspielen eines Upgrades empfohlen."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 4.8,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0"
              }
            },
            {
              "cvssV3_1": {
                "baseScore": 2.4,
                "baseSeverity": "LOW",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N",
                "version": "3.1"
              }
            },
            {
              "cvssV3_0": {
                "baseScore": 2.4,
                "baseSeverity": "LOW",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N",
                "version": "3.0"
              }
            },
            {
              "cvssV2_0": {
                "baseScore": 3.3,
                "vectorString": "AV:N/AC:L/Au:M/C:N/I:P/A:N",
                "version": "2.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-79",
                  "description": "Cross Site Scripting",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-94",
                  "description": "Code Injection",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-04-03T13:31:04.529Z",
            "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
            "shortName": "VulDB"
          },
          "references": [
            {
              "name": "VDB-303101 | Intelbras WRN 150 Wireless Menu cross site scripting",
              "tags": [
                "vdb-entry",
                "technical-description"
              ],
              "url": "https://vuldb.com/?id.303101"
            },
            {
              "name": "VDB-303101 | CTI Indicators (IOB, IOC, TTP, IOA)",
              "tags": [
                "signature",
                "permissions-required"
              ],
              "url": "https://vuldb.com/?ctiid.303101"
            },
            {
              "name": "Submit #501902 | Intelbras WRN 150 V1.0.15_pt_ITB01 Cross Site Scripting",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/?submit.501902"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2025-04-03T00:00:00.000Z",
              "value": "Advisory disclosed"
            },
            {
              "lang": "en",
              "time": "2025-04-03T02:00:00.000Z",
              "value": "VulDB entry created"
            },
            {
              "lang": "en",
              "time": "2025-04-03T08:05:15.000Z",
              "value": "VulDB entry last update"
            }
          ],
          "title": "Intelbras WRN 150 Wireless Menu cross site scripting"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "assignerShortName": "VulDB",
        "cveId": "CVE-2025-3157",
        "datePublished": "2025-04-03T13:31:04.529Z",
        "dateReserved": "2025-04-03T05:59:48.128Z",
        "dateUpdated": "2025-04-03T15:41:39.365Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2025-0784 (GCVE-0-2025-0784)

    Vulnerability from nvd – Published: 2025-01-28 20:00 – Updated: 2025-02-12 20:01
    VLAI
    Title
    Intelbras InControl Registered User usuario cleartext transmission
    Summary
    A vulnerability has been found in Intelbras InControl up to 2.21.58 and classified as problematic. This vulnerability affects unknown code of the file /v1/usuario/ of the component Registered User Handler. The manipulation leads to cleartext transmission of sensitive information. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. Upgrading to version 2.21.59 is able to address this issue. It is recommended to upgrade the affected component.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-01-28 20:32 UTC
    CWE
    • CWE-319 - Cleartext Transmission of Sensitive Information
    • CWE-310 - Cryptographic Issues
    References
    Impacted products
    Vendor Product Version
    Intelbras InControl Affected: 2.21.0
    Affected: 2.21.1
    Affected: 2.21.2
    Affected: 2.21.3
    Affected: 2.21.4
    Affected: 2.21.5
    Affected: 2.21.6
    Affected: 2.21.7
    Affected: 2.21.8
    Affected: 2.21.9
    Affected: 2.21.10
    Affected: 2.21.11
    Affected: 2.21.12
    Affected: 2.21.13
    Affected: 2.21.14
    Affected: 2.21.15
    Affected: 2.21.16
    Affected: 2.21.17
    Affected: 2.21.18
    Affected: 2.21.19
    Affected: 2.21.20
    Affected: 2.21.21
    Affected: 2.21.22
    Affected: 2.21.23
    Affected: 2.21.24
    Affected: 2.21.25
    Affected: 2.21.26
    Affected: 2.21.27
    Affected: 2.21.28
    Affected: 2.21.29
    Affected: 2.21.30
    Affected: 2.21.31
    Affected: 2.21.32
    Affected: 2.21.33
    Affected: 2.21.34
    Affected: 2.21.35
    Affected: 2.21.36
    Affected: 2.21.37
    Affected: 2.21.38
    Affected: 2.21.39
    Affected: 2.21.40
    Affected: 2.21.41
    Affected: 2.21.42
    Affected: 2.21.43
    Affected: 2.21.44
    Affected: 2.21.45
    Affected: 2.21.46
    Affected: 2.21.47
    Affected: 2.21.48
    Affected: 2.21.49
    Affected: 2.21.50
    Affected: 2.21.51
    Affected: 2.21.52
    Affected: 2.21.53
    Affected: 2.21.54
    Affected: 2.21.55
    Affected: 2.21.56
    Affected: 2.21.57
    Affected: 2.21.58
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-0784",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-01-28T20:32:08.923755Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-02-12T20:01:10.799Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "modules": [
                "Registered User Handler"
              ],
              "product": "InControl",
              "vendor": "Intelbras",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.21.0"
                },
                {
                  "status": "affected",
                  "version": "2.21.1"
                },
                {
                  "status": "affected",
                  "version": "2.21.2"
                },
                {
                  "status": "affected",
                  "version": "2.21.3"
                },
                {
                  "status": "affected",
                  "version": "2.21.4"
                },
                {
                  "status": "affected",
                  "version": "2.21.5"
                },
                {
                  "status": "affected",
                  "version": "2.21.6"
                },
                {
                  "status": "affected",
                  "version": "2.21.7"
                },
                {
                  "status": "affected",
                  "version": "2.21.8"
                },
                {
                  "status": "affected",
                  "version": "2.21.9"
                },
                {
                  "status": "affected",
                  "version": "2.21.10"
                },
                {
                  "status": "affected",
                  "version": "2.21.11"
                },
                {
                  "status": "affected",
                  "version": "2.21.12"
                },
                {
                  "status": "affected",
                  "version": "2.21.13"
                },
                {
                  "status": "affected",
                  "version": "2.21.14"
                },
                {
                  "status": "affected",
                  "version": "2.21.15"
                },
                {
                  "status": "affected",
                  "version": "2.21.16"
                },
                {
                  "status": "affected",
                  "version": "2.21.17"
                },
                {
                  "status": "affected",
                  "version": "2.21.18"
                },
                {
                  "status": "affected",
                  "version": "2.21.19"
                },
                {
                  "status": "affected",
                  "version": "2.21.20"
                },
                {
                  "status": "affected",
                  "version": "2.21.21"
                },
                {
                  "status": "affected",
                  "version": "2.21.22"
                },
                {
                  "status": "affected",
                  "version": "2.21.23"
                },
                {
                  "status": "affected",
                  "version": "2.21.24"
                },
                {
                  "status": "affected",
                  "version": "2.21.25"
                },
                {
                  "status": "affected",
                  "version": "2.21.26"
                },
                {
                  "status": "affected",
                  "version": "2.21.27"
                },
                {
                  "status": "affected",
                  "version": "2.21.28"
                },
                {
                  "status": "affected",
                  "version": "2.21.29"
                },
                {
                  "status": "affected",
                  "version": "2.21.30"
                },
                {
                  "status": "affected",
                  "version": "2.21.31"
                },
                {
                  "status": "affected",
                  "version": "2.21.32"
                },
                {
                  "status": "affected",
                  "version": "2.21.33"
                },
                {
                  "status": "affected",
                  "version": "2.21.34"
                },
                {
                  "status": "affected",
                  "version": "2.21.35"
                },
                {
                  "status": "affected",
                  "version": "2.21.36"
                },
                {
                  "status": "affected",
                  "version": "2.21.37"
                },
                {
                  "status": "affected",
                  "version": "2.21.38"
                },
                {
                  "status": "affected",
                  "version": "2.21.39"
                },
                {
                  "status": "affected",
                  "version": "2.21.40"
                },
                {
                  "status": "affected",
                  "version": "2.21.41"
                },
                {
                  "status": "affected",
                  "version": "2.21.42"
                },
                {
                  "status": "affected",
                  "version": "2.21.43"
                },
                {
                  "status": "affected",
                  "version": "2.21.44"
                },
                {
                  "status": "affected",
                  "version": "2.21.45"
                },
                {
                  "status": "affected",
                  "version": "2.21.46"
                },
                {
                  "status": "affected",
                  "version": "2.21.47"
                },
                {
                  "status": "affected",
                  "version": "2.21.48"
                },
                {
                  "status": "affected",
                  "version": "2.21.49"
                },
                {
                  "status": "affected",
                  "version": "2.21.50"
                },
                {
                  "status": "affected",
                  "version": "2.21.51"
                },
                {
                  "status": "affected",
                  "version": "2.21.52"
                },
                {
                  "status": "affected",
                  "version": "2.21.53"
                },
                {
                  "status": "affected",
                  "version": "2.21.54"
                },
                {
                  "status": "affected",
                  "version": "2.21.55"
                },
                {
                  "status": "affected",
                  "version": "2.21.56"
                },
                {
                  "status": "affected",
                  "version": "2.21.57"
                },
                {
                  "status": "affected",
                  "version": "2.21.58"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "eldruin (VulDB User)"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A vulnerability has been found in Intelbras InControl up to 2.21.58 and classified as problematic. This vulnerability affects unknown code of the file /v1/usuario/ of the component Registered User Handler. The manipulation leads to cleartext transmission of sensitive information. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. Upgrading to version 2.21.59 is able to address this issue. It is recommended to upgrade the affected component."
            },
            {
              "lang": "de",
              "value": "In Intelbras InControl bis 2.21.58 wurde eine problematische Schwachstelle gefunden. Dabei geht es um eine nicht genauer bekannte Funktion der Datei /v1/usuario/ der Komponente Registered User Handler. Durch Beeinflussen mit unbekannten Daten kann eine cleartext transmission of sensitive information-Schwachstelle ausgenutzt werden. Die Umsetzung des Angriffs kann dabei \u00fcber das Netzwerk erfolgen. Die Komplexit\u00e4t eines Angriffs ist eher hoch. Das Ausnutzen gilt als schwierig. Der Exploit steht zur \u00f6ffentlichen Verf\u00fcgung. Ein Aktualisieren auf die Version 2.21.59 vermag dieses Problem zu l\u00f6sen. Als bestm\u00f6gliche Massnahme wird das Einspielen eines Upgrades empfohlen."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 6.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0"
              }
            },
            {
              "cvssV3_1": {
                "baseScore": 3.7,
                "baseSeverity": "LOW",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
                "version": "3.1"
              }
            },
            {
              "cvssV3_0": {
                "baseScore": 3.7,
                "baseSeverity": "LOW",
                "vectorString": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
                "version": "3.0"
              }
            },
            {
              "cvssV2_0": {
                "baseScore": 2.6,
                "vectorString": "AV:N/AC:H/Au:N/C:P/I:N/A:N",
                "version": "2.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-319",
                  "description": "Cleartext Transmission of Sensitive Information",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-310",
                  "description": "Cryptographic Issues",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-01-28T20:00:13.220Z",
            "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
            "shortName": "VulDB"
          },
          "references": [
            {
              "name": "VDB-293908 | Intelbras InControl Registered User usuario cleartext transmission",
              "tags": [
                "vdb-entry"
              ],
              "url": "https://vuldb.com/?id.293908"
            },
            {
              "name": "VDB-293908 | CTI Indicators (IOB, IOC, TTP, IOA)",
              "tags": [
                "signature",
                "permissions-required"
              ],
              "url": "https://vuldb.com/?ctiid.293908"
            },
            {
              "name": "Submit #483835 | Intelbras InControl 2.21.57 Cleartext Transmission of Sensitive Information",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/?submit.483835"
            },
            {
              "tags": [
                "exploit"
              ],
              "url": "https://eldruin.notion.site/Intelbras-InControl-v2-21-57-Password-exposed-in-clear-text-17d27474cccb806fba1efda195c78258?pvs=4"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2025-01-28T00:00:00.000Z",
              "value": "Advisory disclosed"
            },
            {
              "lang": "en",
              "time": "2025-01-28T01:00:00.000Z",
              "value": "VulDB entry created"
            },
            {
              "lang": "en",
              "time": "2025-01-28T15:05:34.000Z",
              "value": "VulDB entry last update"
            }
          ],
          "title": "Intelbras InControl Registered User usuario cleartext transmission"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "assignerShortName": "VulDB",
        "cveId": "CVE-2025-0784",
        "datePublished": "2025-01-28T20:00:13.220Z",
        "dateReserved": "2025-01-28T13:59:47.508Z",
        "dateUpdated": "2025-02-12T20:01:10.799Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-12897 (GCVE-0-2024-12897)

    Vulnerability from nvd – Published: 2024-12-22 23:31 – Updated: 2024-12-27 08:51 Unsupported When Assigned
    VLAI
    Title
    Intelbras VIP S4320 G2 Web Interface Sha1Account1 path traversal
    Summary
    A vulnerability was found in Intelbras VIP S3020 G2, VIP S4020 G2, VIP S4020 G3 and VIP S4320 G2 up to 20241222. It has been classified as critical. This affects an unknown part of the file ../mtd/Config/Sha1Account1 of the component Web Interface. The manipulation leads to path traversal: '../filedir'. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-12-24 16:00 UTC
    CWE
    • CWE-24 - Path Traversal: '../filedir'
    • CWE-23 - Relative Path Traversal
    References
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-12897",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-12-24T16:00:18.160289Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-12-24T16:00:32.149Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://netsecfish.notion.site/Path-Traversal-Vulnerability-in-IntelBras-IP-Cameras-mtd-Config-Sha1Account1-and-mtd-Confi-15e6b683e67c80809442ee3425f753b7"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "modules": [
                "Web Interface"
              ],
              "product": "VIP S3020 G2",
              "vendor": "Intelbras",
              "versions": [
                {
                  "status": "affected",
                  "version": "20241222"
                }
              ]
            },
            {
              "modules": [
                "Web Interface"
              ],
              "product": "VIP S4020 G2",
              "vendor": "Intelbras",
              "versions": [
                {
                  "status": "affected",
                  "version": "20241222"
                }
              ]
            },
            {
              "modules": [
                "Web Interface"
              ],
              "product": "VIP S4020 G3",
              "vendor": "Intelbras",
              "versions": [
                {
                  "status": "affected",
                  "version": "20241222"
                }
              ]
            },
            {
              "modules": [
                "Web Interface"
              ],
              "product": "VIP S4320 G2",
              "vendor": "Intelbras",
              "versions": [
                {
                  "status": "affected",
                  "version": "20241222"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "netsecfish (VulDB User)"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A vulnerability was found in Intelbras VIP S3020 G2, VIP S4020 G2, VIP S4020 G3 and VIP S4320 G2 up to 20241222. It has been classified as critical. This affects an unknown part of the file ../mtd/Config/Sha1Account1 of the component Web Interface. The manipulation leads to path traversal: \u0027../filedir\u0027. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used."
            },
            {
              "lang": "de",
              "value": "Es wurde eine Schwachstelle in Intelbras VIP S3020 G2, VIP S4020 G2, VIP S4020 G3 and VIP S4320 G2 bis 20241222 ausgemacht. Sie wurde als kritisch eingestuft. Es geht dabei um eine nicht klar definierte Funktion der Datei ../mtd/Config/Sha1Account1 der Komponente Web Interface. Durch Beeinflussen mit unbekannten Daten kann eine path traversal: \u0027../filedir\u0027-Schwachstelle ausgenutzt werden. Der Angriff kann \u00fcber das Netzwerk passieren. Der Exploit steht zur \u00f6ffentlichen Verf\u00fcgung."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0"
              }
            },
            {
              "cvssV3_1": {
                "baseScore": 4.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
                "version": "3.1"
              }
            },
            {
              "cvssV3_0": {
                "baseScore": 4.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
                "version": "3.0"
              }
            },
            {
              "cvssV2_0": {
                "baseScore": 4,
                "vectorString": "AV:N/AC:L/Au:S/C:P/I:N/A:N",
                "version": "2.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-24",
                  "description": "Path Traversal: \u0027../filedir\u0027",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-23",
                  "description": "Relative Path Traversal",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-12-27T08:51:42.245Z",
            "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
            "shortName": "VulDB"
          },
          "references": [
            {
              "name": "VDB-289167 | Intelbras VIP S4320 G2 Web Interface Sha1Account1 path traversal",
              "tags": [
                "vdb-entry",
                "technical-description"
              ],
              "url": "https://vuldb.com/?id.289167"
            },
            {
              "name": "VDB-289167 | CTI Indicators (IOB, IOC, TTP, IOA)",
              "tags": [
                "signature",
                "permissions-required"
              ],
              "url": "https://vuldb.com/?ctiid.289167"
            },
            {
              "name": "Submit #464260 | IntelBras  IPC-HFW1200S, IPC-HFW2300R-Z, IPC-HFW5220E-Z, IPC-HDW1200S, VIP S3020 G2, VIP S4020 G2, VIP S4320 G2, VIP S4020 G3 WebVersion: 3.2.1.225946; WebVersion: 3.2.1.291804 Path Traversal",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/?submit.464260"
            },
            {
              "tags": [
                "exploit"
              ],
              "url": "https://netsecfish.notion.site/Path-Traversal-Vulnerability-in-IntelBras-IP-Cameras-mtd-Config-Sha1Account1-and-mtd-Confi-15e6b683e67c80809442ee3425f753b7?pvs=4"
            }
          ],
          "tags": [
            "unsupported-when-assigned"
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2024-12-22T00:00:00.000Z",
              "value": "Advisory disclosed"
            },
            {
              "lang": "en",
              "time": "2024-12-22T01:00:00.000Z",
              "value": "VulDB entry created"
            },
            {
              "lang": "en",
              "time": "2024-12-27T09:56:32.000Z",
              "value": "VulDB entry last update"
            }
          ],
          "title": "Intelbras VIP S4320 G2 Web Interface Sha1Account1 path traversal"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "assignerShortName": "VulDB",
        "cveId": "CVE-2024-12897",
        "datePublished": "2024-12-22T23:31:05.102Z",
        "dateReserved": "2024-12-22T08:47:43.200Z",
        "dateUpdated": "2024-12-27T08:51:42.245Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-12896 (GCVE-0-2024-12896)

    Vulnerability from nvd – Published: 2024-12-22 23:00 – Updated: 2024-12-24 16:07 Unsupported When Assigned
    VLAI
    Title
    Intelbras VIP S4320 G2 Web Interface webCapsConfig information disclosure
    Summary
    A vulnerability was found in Intelbras VIP S3020 G2, VIP S4020 G2, VIP S4020 G3 and VIP S4320 G2 up to 20241222 and classified as problematic. Affected by this issue is some unknown functionality of the file /web_caps/webCapsConfig of the component Web Interface. The manipulation leads to information disclosure. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor assesses that "the information disclosed in the URL is not sensitive or poses any risk to the user".
    SSVC
    Exploitation: poc Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-12-24 16:07 UTC
    CWE
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-12896",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-12-24T16:07:43.746824Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-12-24T16:07:59.581Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://netsecfish.notion.site/IntelBras-IP-Camera-Information-Disclosure-15e6b683e67c80a89f89daf59daa9ea8"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "modules": [
                "Web Interface"
              ],
              "product": "VIP S3020 G2",
              "vendor": "Intelbras",
              "versions": [
                {
                  "status": "affected",
                  "version": "20241222"
                }
              ]
            },
            {
              "modules": [
                "Web Interface"
              ],
              "product": "VIP S4020 G2",
              "vendor": "Intelbras",
              "versions": [
                {
                  "status": "affected",
                  "version": "20241222"
                }
              ]
            },
            {
              "modules": [
                "Web Interface"
              ],
              "product": "VIP S4020 G3",
              "vendor": "Intelbras",
              "versions": [
                {
                  "status": "affected",
                  "version": "20241222"
                }
              ]
            },
            {
              "modules": [
                "Web Interface"
              ],
              "product": "VIP S4320 G2",
              "vendor": "Intelbras",
              "versions": [
                {
                  "status": "affected",
                  "version": "20241222"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "netsecfish (VulDB User)"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A vulnerability was found in Intelbras VIP S3020 G2, VIP S4020 G2, VIP S4020 G3 and VIP S4320 G2 up to 20241222 and classified as problematic. Affected by this issue is some unknown functionality of the file /web_caps/webCapsConfig of the component Web Interface. The manipulation leads to information disclosure. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor assesses that \"the information disclosed in the URL is not sensitive or poses any risk to the user\"."
            },
            {
              "lang": "de",
              "value": "Eine Schwachstelle wurde in Intelbras VIP S3020 G2, VIP S4020 G2, VIP S4020 G3 and VIP S4320 G2 bis 20241222 gefunden. Sie wurde als problematisch eingestuft. Es geht hierbei um eine nicht n\u00e4her spezifizierte Funktion der Datei /web_caps/webCapsConfig der Komponente Web Interface. Durch das Beeinflussen mit unbekannten Daten kann eine information disclosure-Schwachstelle ausgenutzt werden. Der Angriff kann \u00fcber das Netzwerk angegangen werden. Der Exploit steht zur \u00f6ffentlichen Verf\u00fcgung."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 6.9,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0"
              }
            },
            {
              "cvssV3_1": {
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
                "version": "3.1"
              }
            },
            {
              "cvssV3_0": {
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
                "version": "3.0"
              }
            },
            {
              "cvssV2_0": {
                "baseScore": 5,
                "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
                "version": "2.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-200",
                  "description": "Information Disclosure",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-284",
                  "description": "Improper Access Controls",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-12-22T23:00:12.200Z",
            "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
            "shortName": "VulDB"
          },
          "references": [
            {
              "name": "VDB-289166 | Intelbras VIP S4320 G2 Web Interface webCapsConfig information disclosure",
              "tags": [
                "vdb-entry"
              ],
              "url": "https://vuldb.com/?id.289166"
            },
            {
              "name": "VDB-289166 | CTI Indicators (IOB, IOC, TTP, IOA)",
              "tags": [
                "signature",
                "permissions-required"
              ],
              "url": "https://vuldb.com/?ctiid.289166"
            },
            {
              "name": "Submit #464258 | IntelBras VIP S3020 G2, VIP S4020 G2, VIP S4320 G2, VIP S4020 G3, IPC-HFW1200S, IPC-HFW2300R-Z, IPC-HFW5220E-Z, IPC-HDW1200S N/A Information Disclosure",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/?submit.464258"
            },
            {
              "tags": [
                "exploit"
              ],
              "url": "https://netsecfish.notion.site/IntelBras-IP-Camera-Information-Disclosure-15e6b683e67c80a89f89daf59daa9ea8?pvs=73"
            }
          ],
          "tags": [
            "unsupported-when-assigned"
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2024-12-22T00:00:00.000Z",
              "value": "Advisory disclosed"
            },
            {
              "lang": "en",
              "time": "2024-12-22T01:00:00.000Z",
              "value": "VulDB entry created"
            },
            {
              "lang": "en",
              "time": "2024-12-22T09:53:48.000Z",
              "value": "VulDB entry last update"
            }
          ],
          "title": "Intelbras VIP S4320 G2 Web Interface webCapsConfig information disclosure"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "assignerShortName": "VulDB",
        "cveId": "CVE-2024-12896",
        "datePublished": "2024-12-22T23:00:12.200Z",
        "dateReserved": "2024-12-22T08:47:39.237Z",
        "dateUpdated": "2024-12-24T16:07:59.581Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2026-101265 (GCVE-0-2026-101265)

    Vulnerability from cvelistv5 – Published: 2026-09-28 23:30 – Updated: 2026-09-29 12:08
    VLAI
    Title
    Intelbras TIP 125i Básico sensitive information in source
    Summary
    A vulnerability was identified in Intelbras TIP 125i 4.3.35/4.3.41. The affected element is an unknown function of the component Básico Page. Such manipulation leads to inclusion of sensitive information in source code. The attack can be launched remotely. A high complexity level is associated with this attack. The exploitability is described as difficult. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-29 12:07 UTC
    CWE
    • CWE-540 - Inclusion of Sensitive Information in Source Code
    • CWE-200 - Information Disclosure
    References
    URL Tags
    https://vuldb.com/vuln/411033 vdb-entry
    https://vuldb.com/vuln/411033/cti signaturepermissions-required
    https://vuldb.com/cve/CVE-2026-101265 third-party-advisory
    https://vuldb.com/submit/916125 third-party-advisory
    Impacted products
    Vendor Product Version
    Intelbras TIP 125i Affected: 4.3.35
    Affected: 4.3.41
        cpe:2.3:h:intelbras:tip_125i:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-101265",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-29T12:07:58.106106Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-29T12:08:26.960Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://vuldb.com/submit/916125"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:h:intelbras:tip_125i:*:*:*:*:*:*:*:*"
              ],
              "modules": [
                "B\u00e1sico Page"
              ],
              "product": "TIP 125i",
              "vendor": "Intelbras",
              "versions": [
                {
                  "status": "affected",
                  "version": "4.3.35"
                },
                {
                  "status": "affected",
                  "version": "4.3.41"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "TheL4zyF0x (VulDB User)"
            },
            {
              "lang": "en",
              "type": "coordinator",
              "value": "VulDB CNA Team"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A vulnerability was identified in Intelbras TIP 125i 4.3.35/4.3.41. The affected element is an unknown function of the component B\u00e1sico Page. Such manipulation leads to inclusion of sensitive information in source code. The attack can be launched remotely. A high complexity level is associated with this attack. The exploitability is described as difficult. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 2.3,
                "baseSeverity": "LOW",
                "vectorString": "CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P",
                "version": "4.0"
              }
            },
            {
              "cvssV3_1": {
                "baseScore": 3.1,
                "baseSeverity": "LOW",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R",
                "version": "3.1"
              }
            },
            {
              "cvssV3_0": {
                "baseScore": 3.1,
                "baseSeverity": "LOW",
                "vectorString": "CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R",
                "version": "3.0"
              }
            },
            {
              "cvssV2_0": {
                "baseScore": 2.1,
                "vectorString": "AV:N/AC:H/Au:S/C:P/I:N/A:N/E:POC/RL:ND/RC:UR",
                "version": "2.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-540",
                  "description": "Inclusion of Sensitive Information in Source Code",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-200",
                  "description": "Information Disclosure",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-28T23:30:10.163Z",
            "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
            "shortName": "VulDB"
          },
          "references": [
            {
              "name": "VDB-411033 | Intelbras TIP 125i B\u00e1sico sensitive information in source",
              "tags": [
                "vdb-entry"
              ],
              "url": "https://vuldb.com/vuln/411033"
            },
            {
              "name": "VDB-411033 | CTI Indicators (IOB, IOC, TTP)",
              "tags": [
                "signature",
                "permissions-required"
              ],
              "url": "https://vuldb.com/vuln/411033/cti"
            },
            {
              "name": "CVE-2026-101265 | CVE Analysis and Report",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/cve/CVE-2026-101265"
            },
            {
              "name": "Submit #916125 | Intelbras Intelbras TIP125_I 4.3.35/4.3.41 Sensitive Data Exposure",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/submit/916125"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-09-28T00:00:00.000Z",
              "value": "Advisory disclosed"
            },
            {
              "lang": "en",
              "time": "2026-09-28T02:00:00.000Z",
              "value": "VulDB entry created"
            },
            {
              "lang": "en",
              "time": "2026-09-28T13:46:12.000Z",
              "value": "VulDB entry last update"
            }
          ],
          "title": "Intelbras TIP 125i B\u00e1sico sensitive information in source",
          "x_generator": [
            "VulDB PVTS v202609"
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "assignerShortName": "VulDB",
        "cveId": "CVE-2026-101265",
        "datePublished": "2026-09-28T23:30:10.163Z",
        "dateReserved": "2026-09-28T11:41:07.968Z",
        "dateUpdated": "2026-09-29T12:08:26.960Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-12211 (GCVE-0-2026-12211)

    Vulnerability from cvelistv5 – Published: 2026-06-15 02:45 – Updated: 2026-06-15 10:34
    VLAI
    Title
    Intelbras iNVU 7016 FT Web syslog path traversal
    Summary
    A flaw has been found in Intelbras iNVU 7016 FT 3.004.00IB000.0.T Build 2025-09-26. This impacts an unknown function of the file /RPC2_Loadfile/syslog/ of the component Web Interface. Executing a manipulation can lead to path traversal. The attack can be launched remotely. The exploit has been published and may be used. It is recommended to upgrade the affected component. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-06-15 10:34 UTC
    CWE
    Impacted products
    Vendor Product Version
    Intelbras iNVU 7016 FT Affected: 3.004.00IB000.0.T Build 2025-09-26
        cpe:2.3:h:intelbras:invu_7016_ft:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-12211",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-06-15T10:34:27.235437Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-06-15T10:34:51.316Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:h:intelbras:invu_7016_ft:*:*:*:*:*:*:*:*"
              ],
              "modules": [
                "Web Interface"
              ],
              "product": "iNVU 7016 FT",
              "vendor": "Intelbras",
              "versions": [
                {
                  "status": "affected",
                  "version": "3.004.00IB000.0.T Build 2025-09-26"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "coaglio (VulDB User)"
            },
            {
              "lang": "en",
              "type": "coordinator",
              "value": "VulDB CNA Team"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A flaw has been found in Intelbras iNVU 7016 FT 3.004.00IB000.0.T Build 2025-09-26. This impacts an unknown function of the file /RPC2_Loadfile/syslog/ of the component Web Interface. Executing a manipulation can lead to path traversal. The attack can be launched remotely. The exploit has been published and may be used. It is recommended to upgrade the affected component. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 5.1,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P",
                "version": "4.0"
              }
            },
            {
              "cvssV3_1": {
                "baseScore": 2.7,
                "baseSeverity": "LOW",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C",
                "version": "3.1"
              }
            },
            {
              "cvssV3_0": {
                "baseScore": 2.7,
                "baseSeverity": "LOW",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C",
                "version": "3.0"
              }
            },
            {
              "cvssV2_0": {
                "baseScore": 3.3,
                "vectorString": "AV:N/AC:L/Au:M/C:P/I:N/A:N/E:POC/RL:OF/RC:C",
                "version": "2.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-22",
                  "description": "Path Traversal",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-06-15T02:45:08.782Z",
            "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
            "shortName": "VulDB"
          },
          "references": [
            {
              "name": "VDB-370853 | Intelbras iNVU 7016 FT Web syslog path traversal",
              "tags": [
                "vdb-entry"
              ],
              "url": "https://vuldb.com/vuln/370853"
            },
            {
              "name": "VDB-370853 | CTI Indicators (IOB, IOC, TTP, IOA)",
              "tags": [
                "signature",
                "permissions-required"
              ],
              "url": "https://vuldb.com/vuln/370853/cti"
            },
            {
              "name": "CVE-2026-12211 | CVE Analysis and Report",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/cve/CVE-2026-12211"
            },
            {
              "name": "Submit #832544 | Intelbras iNVU 7016 FT 3.004.00IB000.0.T (Build 2025-09-26) Path Traversal",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/submit/832544"
            },
            {
              "tags": [
                "exploit"
              ],
              "url": "https://coaglio.com/writeups/lfi-intelbras-invu.html"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "http://api-cronos.intelbras.com.br/download/INVU/INVU7016FT/prod/INVU7016FT-2026.05.29-712953bf2bb2af7e72d0577ad5ef6455.260527.BIN"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-06-14T00:00:00.000Z",
              "value": "Advisory disclosed"
            },
            {
              "lang": "en",
              "time": "2026-06-14T02:00:00.000Z",
              "value": "VulDB entry created"
            },
            {
              "lang": "en",
              "time": "2026-06-14T14:38:47.000Z",
              "value": "VulDB entry last update"
            }
          ],
          "title": "Intelbras iNVU 7016 FT Web syslog path traversal"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "assignerShortName": "VulDB",
        "cveId": "CVE-2026-12211",
        "datePublished": "2026-06-15T02:45:08.782Z",
        "dateReserved": "2026-06-14T12:32:49.466Z",
        "dateUpdated": "2026-06-15T10:34:51.316Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2019-25472 (GCVE-0-2019-25472)

    Vulnerability from cvelistv5 – Published: 2026-03-11 18:23 – Updated: 2026-04-07 14:04
    VLAI
    Title
    IntelBras Telefone IP TIP200/200 LITE Arbitrary File Read via dumpConfigFile
    Summary
    IntelBras Telefone IP TIP200 and 200 LITE contain an unauthenticated arbitrary file read vulnerability in the dumpConfigFile function accessible via the cgiServer.exx endpoint. Attackers can send GET requests to /cgi-bin/cgiServer.exx with the command parameter containing dumpConfigFile() to read sensitive files including /etc/shadow and configuration files without proper authorization.
    SSVC
    Exploitation: poc Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-03-11 18:46 UTC
    CWE
    • CWE-73 - External Control of File Name or Path
    Date Public
    2019-09-02 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2019-25472",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-03-11T18:46:47.213472Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-03-11T19:31:02.474Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Telefone IP TIP 200",
              "vendor": "Intelbras",
              "versions": [
                {
                  "status": "affected",
                  "version": "*"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Telefone IP TIP 200 LITE",
              "vendor": "Intelbras",
              "versions": [
                {
                  "status": "affected",
                  "version": "*"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Todor Donev"
            }
          ],
          "datePublic": "2019-09-02T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eIntelBras Telefone IP TIP200 and 200 LITE contain an unauthenticated arbitrary file read vulnerability in the dumpConfigFile function accessible via the cgiServer.exx endpoint. Attackers can send GET requests to /cgi-bin/cgiServer.exx with the command parameter containing dumpConfigFile() to read sensitive files including /etc/shadow and configuration files without proper authorization.\u003c/p\u003e"
                }
              ],
              "value": "IntelBras Telefone IP TIP200 and 200 LITE contain an unauthenticated arbitrary file read vulnerability in the dumpConfigFile function accessible via the cgiServer.exx endpoint. Attackers can send GET requests to /cgi-bin/cgiServer.exx with the command parameter containing dumpConfigFile() to read sensitive files including /etc/shadow and configuration files without proper authorization."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.7,
                "baseSeverity": "HIGH",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "NONE",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-73",
                  "description": "CWE-73 External Control of File Name or Path",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-04-07T14:04:29.982Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "ExploitDB-47337",
              "tags": [
                "exploit"
              ],
              "url": "https://www.exploit-db.com/exploits/47337"
            },
            {
              "name": "Intelbras Product Documentation",
              "tags": [
                "product"
              ],
              "url": "https://backend.intelbras.com/sites/default/files/integration/lamina_tip-200-lite_e_tip-200.pdf"
            },
            {
              "name": "VulnCheck Advisory: IntelBras Telefone IP TIP200/200 LITE Arbitrary File Read via dumpConfigFile",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/intelbras-telefone-ip-tip200-200-lite-arbitrary-file-read-via-dumpconfigfile"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "IntelBras Telefone IP TIP200/200 LITE Arbitrary File Read via dumpConfigFile",
          "x_generator": {
            "engine": "vulncheck"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2019-25472",
        "datePublished": "2026-03-11T18:23:15.474Z",
        "dateReserved": "2026-02-22T14:43:03.387Z",
        "dateUpdated": "2026-04-07T14:04:29.982Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-2564 (GCVE-0-2026-2564)

    Vulnerability from cvelistv5 – Published: 2026-02-16 16:02 – Updated: 2026-02-23 10:12
    VLAI
    Title
    Intelbras VIP 3260 Z IA OutsideCmd password recovery
    Summary
    A security flaw has been discovered in Intelbras VIP 3260 Z IA 2.840.00IB005.0.T. Affected by this vulnerability is an unknown functionality of the file /OutsideCmd. The manipulation results in weak password recovery. It is possible to launch the attack remotely. Attacks of this nature are highly complex. The exploitation appears to be difficult. It is recommended to upgrade the affected component.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-02-17 14:54 UTC
    CWE
    References
    URL Tags
    https://vuldb.com/?id.346171 vdb-entry
    https://vuldb.com/?ctiid.346171 signaturepermissions-required
    https://vuldb.com/?submit.741776 third-party-advisory
    Impacted products
    Vendor Product Version
    Intelbras VIP 3260 Z IA Affected: 2.840.00IB005.0.T
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-2564",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-02-17T14:54:28.001175Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-02-17T14:54:37.992Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "VIP 3260 Z IA",
              "vendor": "Intelbras",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.840.00IB005.0.T"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "ak7r4 (VulDB User)"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A security flaw has been discovered in Intelbras VIP 3260 Z IA 2.840.00IB005.0.T. Affected by this vulnerability is an unknown functionality of the file /OutsideCmd. The manipulation results in weak password recovery. It is possible to launch the attack remotely. Attacks of this nature are highly complex. The exploitation appears to be difficult. It is recommended to upgrade the affected component."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 9.2,
                "baseSeverity": "CRITICAL",
                "vectorString": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X",
                "version": "4.0"
              }
            },
            {
              "cvssV3_1": {
                "baseScore": 8.1,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:X/RL:O/RC:C",
                "version": "3.1"
              }
            },
            {
              "cvssV3_0": {
                "baseScore": 8.1,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:X/RL:O/RC:C",
                "version": "3.0"
              }
            },
            {
              "cvssV2_0": {
                "baseScore": 7.6,
                "vectorString": "AV:N/AC:H/Au:N/C:C/I:C/A:C/E:ND/RL:OF/RC:C",
                "version": "2.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-640",
                  "description": "Weak Password Recovery",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-02-23T10:12:32.594Z",
            "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
            "shortName": "VulDB"
          },
          "references": [
            {
              "name": "VDB-346171 | Intelbras VIP 3260 Z IA OutsideCmd password recovery",
              "tags": [
                "vdb-entry"
              ],
              "url": "https://vuldb.com/?id.346171"
            },
            {
              "name": "VDB-346171 | CTI Indicators (IOB, IOC, TTP, IOA)",
              "tags": [
                "signature",
                "permissions-required"
              ],
              "url": "https://vuldb.com/?ctiid.346171"
            },
            {
              "name": "Submit #741776 | Intelbras VIP 3260 Z IA v2.840.00IB005.0.T Weak Password Recovery",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/?submit.741776"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-02-15T00:00:00.000Z",
              "value": "Advisory disclosed"
            },
            {
              "lang": "en",
              "time": "2026-02-15T01:00:00.000Z",
              "value": "VulDB entry created"
            },
            {
              "lang": "en",
              "time": "2026-02-18T15:38:32.000Z",
              "value": "VulDB entry last update"
            }
          ],
          "title": "Intelbras VIP 3260 Z IA OutsideCmd password recovery"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "assignerShortName": "VulDB",
        "cveId": "CVE-2026-2564",
        "datePublished": "2026-02-16T16:02:06.547Z",
        "dateReserved": "2026-02-15T19:22:27.386Z",
        "dateUpdated": "2026-02-23T10:12:32.594Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2020-36963 (GCVE-0-2020-36963)

    Vulnerability from cvelistv5 – Published: 2026-01-28 17:35 – Updated: 2026-07-28 01:47
    VLAI
    Title
    Intelbras Router RF 301K 1.1.2 - Authentication Bypass
    Summary
    Intelbras Router RF 301K firmware version 1.1.2 contains an authentication bypass vulnerability that allows unauthenticated attackers to download router configuration files. Attackers can send a specific HTTP GET request to /cgi-bin/DownloadCfg/RouterCfm.cfg to retrieve sensitive router configuration without authentication.
    SSVC
    Exploitation: poc Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-01-28 18:59 UTC
    CWE
    • CWE-306 - Missing Authentication for Critical Function
    Impacted products
    Vendor Product Version
    Intelbras Intelbras Router RF 301K Affected: firmware version 1.1.2
        cpe:2.3:h:intelbras:rf_301k:firmware:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2020-11-30 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2020-36963",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-01-28T18:59:41.650842Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-01-29T18:12:47.675Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://www.exploit-db.com/exploits/49126"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Intelbras Router RF 301K",
              "vendor": "Intelbras",
              "versions": [
                {
                  "status": "affected",
                  "version": "firmware version 1.1.2"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:h:intelbras:rf_301k:firmware:*:*:*:*:*:*:*",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Kaio Amaral"
            }
          ],
          "datePublic": "2020-11-30T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Intelbras Router RF 301K firmware version 1.1.2 contains an authentication bypass vulnerability that allows unauthenticated attackers to download router configuration files. Attackers can send a specific HTTP GET request to /cgi-bin/DownloadCfg/RouterCfm.cfg to retrieve sensitive router configuration without authentication."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.7,
                "baseSeverity": "HIGH",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "NONE",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-306",
                  "description": "Missing Authentication for Critical Function",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-07-28T01:47:05.787Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "ExploitDB-49126",
              "tags": [
                "exploit"
              ],
              "url": "https://www.exploit-db.com/exploits/49126"
            },
            {
              "name": "Intelbras Official Homepage",
              "tags": [
                "product"
              ],
              "url": "https://www.intelbras.com/pt-br/"
            },
            {
              "name": "VulnCheck Advisory: Intelbras Router RF 301K 1.1.2 - Authentication Bypass",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/intelbras-router-rf-k-authentication-bypass"
            }
          ],
          "title": "Intelbras Router RF 301K 1.1.2 - Authentication Bypass",
          "x_generator": {
            "engine": "vulncheck"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2020-36963",
        "datePublished": "2026-01-28T17:35:08.650Z",
        "dateReserved": "2026-01-27T15:47:07.998Z",
        "dateUpdated": "2026-07-28T01:47:05.787Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-13221 (GCVE-0-2025-13221)

    Vulnerability from cvelistv5 – Published: 2025-11-15 19:32 – Updated: 2026-01-07 16:53
    VLAI
    Title
    Intelbras UnniTI usuarios.xml credentials storage
    Summary
    A weakness has been identified in Intelbras UnniTI 24.07.11. The affected element is an unknown function of the file /xml/sistema/usuarios.xml. Executing manipulation of the argument Usuario/Senha can lead to unprotected storage of credentials. The attack can be executed remotely. The exploit has been made available to the public and could be exploited.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-01-07 16:53 UTC
    CWE
    • CWE-256 - Unprotected Storage of Credentials
    • CWE-255 - Credentials Management
    References
    URL Tags
    https://vuldb.com/?id.332537 vdb-entrytechnical-description
    https://vuldb.com/?ctiid.332537 signaturepermissions-required
    https://vuldb.com/?submit.685825 third-party-advisory
    https://www.notion.so/eldruin/Intelbras-UnniTI-Pl… exploit
    Impacted products
    Vendor Product Version
    Intelbras UnniTI Affected: 24.07.11
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-13221",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-01-07T16:53:06.187300Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-01-07T16:53:16.059Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "UnniTI",
              "vendor": "Intelbras",
              "versions": [
                {
                  "status": "affected",
                  "version": "24.07.11"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "eldruin (VulDB User)"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A weakness has been identified in Intelbras UnniTI 24.07.11. The affected element is an unknown function of the file /xml/sistema/usuarios.xml. Executing manipulation of the argument Usuario/Senha can lead to unprotected storage of credentials. The attack can be executed remotely. The exploit has been made available to the public and could be exploited."
            },
            {
              "lang": "de",
              "value": "Es wurde eine Schwachstelle in Intelbras UnniTI 24.07.11 entdeckt. Davon betroffen ist unbekannter Code der Datei /xml/sistema/usuarios.xml. Durch das Beeinflussen des Arguments Usuario/Senha mit unbekannten Daten kann eine unprotected storage of credentials-Schwachstelle ausgenutzt werden. Die Umsetzung des Angriffs kann dabei \u00fcber das Netzwerk erfolgen. Die Schwachstelle wurde \u00f6ffentlich offengelegt und k\u00f6nnte ausgenutzt werden."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 6.9,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P",
                "version": "4.0"
              }
            },
            {
              "cvssV3_1": {
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:W/RC:R",
                "version": "3.1"
              }
            },
            {
              "cvssV3_0": {
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:W/RC:R",
                "version": "3.0"
              }
            },
            {
              "cvssV2_0": {
                "baseScore": 5,
                "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N/E:POC/RL:W/RC:UR",
                "version": "2.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-256",
                  "description": "Unprotected Storage of Credentials",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-255",
                  "description": "Credentials Management",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-11-15T19:32:05.663Z",
            "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
            "shortName": "VulDB"
          },
          "references": [
            {
              "name": "VDB-332537 | Intelbras UnniTI usuarios.xml credentials storage",
              "tags": [
                "vdb-entry",
                "technical-description"
              ],
              "url": "https://vuldb.com/?id.332537"
            },
            {
              "name": "VDB-332537 | CTI Indicators (IOB, IOC, TTP, IOA)",
              "tags": [
                "signature",
                "permissions-required"
              ],
              "url": "https://vuldb.com/?ctiid.332537"
            },
            {
              "name": "Submit #685825 | Intelbras UnniTI 24.07.11 Unprotected Storage of Credentials",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/?submit.685825"
            },
            {
              "tags": [
                "exploit"
              ],
              "url": "https://www.notion.so/eldruin/Intelbras-UnniTI-Plaintext-Admin-Credentials-Disclosure-29c27474cccb8008b2d7ea60affdf86e?source=copy_link"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2025-11-14T00:00:00.000Z",
              "value": "Advisory disclosed"
            },
            {
              "lang": "en",
              "time": "2025-11-14T01:00:00.000Z",
              "value": "VulDB entry created"
            },
            {
              "lang": "en",
              "time": "2025-11-14T22:19:55.000Z",
              "value": "VulDB entry last update"
            }
          ],
          "title": "Intelbras UnniTI usuarios.xml credentials storage"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "assignerShortName": "VulDB",
        "cveId": "CVE-2025-13221",
        "datePublished": "2025-11-15T19:32:05.663Z",
        "dateReserved": "2025-11-14T21:14:33.763Z",
        "dateUpdated": "2026-01-07T16:53:16.059Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-8515 (GCVE-0-2025-8515)

    Vulnerability from cvelistv5 – Published: 2025-08-04 10:32 – Updated: 2025-10-29 06:53
    VLAI
    Title
    Intelbras InControl JSON Endpoint operador information disclosure
    Summary
    A weakness has been identified in Intelbras InControl 2.21.60.9. This vulnerability affects unknown code of the file /v1/operador/ of the component JSON Endpoint. Executing manipulation can lead to information disclosure. It is possible to launch the attack remotely. A high complexity level is associated with this attack. It is stated that the exploitability is difficult. The exploit has been made available to the public and could be exploited. Upgrading the affected component is advised.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-08-04 14:30 UTC
    CWE
    References
    URL Tags
    https://vuldb.com/?id.318641 vdb-entrytechnical-description
    https://vuldb.com/?ctiid.318641 signaturepermissions-required
    https://vuldb.com/?submit.579544 third-party-advisory
    https://backend.intelbras.com/sites/default/files… related
    Impacted products
    Vendor Product Version
    Intelbras InControl Affected: 2.21.60.9
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-8515",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-08-04T14:30:06.568840Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-08-04T15:00:05.698Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "modules": [
                "JSON Endpoint"
              ],
              "product": "InControl",
              "vendor": "Intelbras",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.21.60.9"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "lorenzomoulin (VulDB User)"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A weakness has been identified in Intelbras InControl 2.21.60.9. This vulnerability affects unknown code of the file /v1/operador/ of the component JSON Endpoint. Executing manipulation can lead to information disclosure. It is possible to launch the attack remotely. A high complexity level is associated with this attack. It is stated that the exploitability is difficult. The exploit has been made available to the public and could be exploited. Upgrading the affected component is advised."
            },
            {
              "lang": "de",
              "value": "Es wurde eine Schwachstelle in Intelbras InControl 2.21.60.9 entdeckt. Davon betroffen ist unbekannter Code der Datei /v1/operador/ der Komponente JSON Endpoint. Dank Manipulation mit unbekannten Daten kann eine information disclosure-Schwachstelle ausgenutzt werden. Die Umsetzung des Angriffs kann dabei \u00fcber das Netzwerk erfolgen. Ein Angriff erfordert eine vergleichsweise hohe Komplexit\u00e4t. Sie gilt als schwierig ausnutzbar. Der Exploit wurde der \u00d6ffentlichkeit bekannt gemacht und k\u00f6nnte verwendet werden. Es wird empfohlen, die betroffene Komponente zu aktualisieren."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 2.3,
                "baseSeverity": "LOW",
                "vectorString": "CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P",
                "version": "4.0"
              }
            },
            {
              "cvssV3_1": {
                "baseScore": 3.1,
                "baseSeverity": "LOW",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C",
                "version": "3.1"
              }
            },
            {
              "cvssV3_0": {
                "baseScore": 3.1,
                "baseSeverity": "LOW",
                "vectorString": "CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C",
                "version": "3.0"
              }
            },
            {
              "cvssV2_0": {
                "baseScore": 2.1,
                "vectorString": "AV:N/AC:H/Au:S/C:P/I:N/A:N/E:POC/RL:OF/RC:C",
                "version": "2.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-200",
                  "description": "Information Disclosure",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-284",
                  "description": "Improper Access Controls",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-10-29T06:53:04.612Z",
            "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
            "shortName": "VulDB"
          },
          "references": [
            {
              "name": "VDB-318641 | Intelbras InControl JSON Endpoint operador information disclosure",
              "tags": [
                "vdb-entry",
                "technical-description"
              ],
              "url": "https://vuldb.com/?id.318641"
            },
            {
              "name": "VDB-318641 | CTI Indicators (IOB, IOC, TTP, IOA)",
              "tags": [
                "signature",
                "permissions-required"
              ],
              "url": "https://vuldb.com/?ctiid.318641"
            },
            {
              "name": "Submit #579544 | Intelbras InControl  2.21.60.9 Information Disclosure",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/?submit.579544"
            },
            {
              "tags": [
                "related"
              ],
              "url": "https://backend.intelbras.com/sites/default/files/2025-08/Aviso%20de%20Seguran%C3%A7a%20-%20Incontrol%202.21.60%20e%202.21.61%20PT-IN%20.pdf"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2025-08-04T00:00:00.000Z",
              "value": "Advisory disclosed"
            },
            {
              "lang": "en",
              "time": "2025-08-04T02:00:00.000Z",
              "value": "VulDB entry created"
            },
            {
              "lang": "en",
              "time": "2025-10-29T07:57:56.000Z",
              "value": "VulDB entry last update"
            }
          ],
          "title": "Intelbras InControl JSON Endpoint operador information disclosure"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "assignerShortName": "VulDB",
        "cveId": "CVE-2025-8515",
        "datePublished": "2025-08-04T10:32:05.124Z",
        "dateReserved": "2025-08-04T05:41:27.160Z",
        "dateUpdated": "2025-10-29T06:53:04.612Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2025-7061 (GCVE-0-2025-7061)

    Vulnerability from cvelistv5 – Published: 2025-07-04 12:32 – Updated: 2025-07-07 16:23
    VLAI
    Title
    Intelbras InControl operador csv injection
    Summary
    A vulnerability was found in Intelbras InControl up to 2.21.60.9. It has been declared as problematic. This vulnerability affects unknown code of the file /v1/operador/. The manipulation leads to csv injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-07-07 16:23 UTC
    CWE
    References
    URL Tags
    https://vuldb.com/?id.314836 vdb-entry
    https://vuldb.com/?ctiid.314836 signaturepermissions-required
    https://vuldb.com/?submit.600881 third-party-advisory
    Impacted products
    Vendor Product Version
    Intelbras InControl Affected: 2.21.60.0
    Affected: 2.21.60.1
    Affected: 2.21.60.2
    Affected: 2.21.60.3
    Affected: 2.21.60.4
    Affected: 2.21.60.5
    Affected: 2.21.60.6
    Affected: 2.21.60.7
    Affected: 2.21.60.8
    Affected: 2.21.60.9
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-7061",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-07-07T16:23:15.540883Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-07-07T16:23:17.934Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://vuldb.com/?submit.600881"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "InControl",
              "vendor": "Intelbras",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.21.60.0"
                },
                {
                  "status": "affected",
                  "version": "2.21.60.1"
                },
                {
                  "status": "affected",
                  "version": "2.21.60.2"
                },
                {
                  "status": "affected",
                  "version": "2.21.60.3"
                },
                {
                  "status": "affected",
                  "version": "2.21.60.4"
                },
                {
                  "status": "affected",
                  "version": "2.21.60.5"
                },
                {
                  "status": "affected",
                  "version": "2.21.60.6"
                },
                {
                  "status": "affected",
                  "version": "2.21.60.7"
                },
                {
                  "status": "affected",
                  "version": "2.21.60.8"
                },
                {
                  "status": "affected",
                  "version": "2.21.60.9"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "lorenzomoulin (VulDB User)"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A vulnerability was found in Intelbras InControl up to 2.21.60.9. It has been declared as problematic. This vulnerability affects unknown code of the file /v1/operador/. The manipulation leads to csv injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way."
            },
            {
              "lang": "de",
              "value": "In Intelbras InControl bis 2.21.60.9 wurde eine Schwachstelle ausgemacht. Sie wurde als problematisch eingestuft. Das betrifft eine unbekannte Funktionalit\u00e4t der Datei /v1/operador/. Mittels dem Manipulieren mit unbekannten Daten kann eine csv injection-Schwachstelle ausgenutzt werden. Der Angriff kann \u00fcber das Netzwerk angegangen werden. Der Exploit steht zur \u00f6ffentlichen Verf\u00fcgung."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 5.1,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P",
                "version": "4.0"
              }
            },
            {
              "cvssV3_1": {
                "baseScore": 2.7,
                "baseSeverity": "LOW",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R",
                "version": "3.1"
              }
            },
            {
              "cvssV3_0": {
                "baseScore": 2.7,
                "baseSeverity": "LOW",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R",
                "version": "3.0"
              }
            },
            {
              "cvssV2_0": {
                "baseScore": 3.3,
                "vectorString": "AV:N/AC:L/Au:M/C:N/I:P/A:N/E:POC/RL:ND/RC:UR",
                "version": "2.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-1236",
                  "description": "CSV Injection",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-74",
                  "description": "Injection",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-07-04T12:32:04.865Z",
            "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
            "shortName": "VulDB"
          },
          "references": [
            {
              "name": "VDB-314836 | Intelbras InControl operador csv injection",
              "tags": [
                "vdb-entry"
              ],
              "url": "https://vuldb.com/?id.314836"
            },
            {
              "name": "VDB-314836 | CTI Indicators (IOB, IOC, IOA)",
              "tags": [
                "signature",
                "permissions-required"
              ],
              "url": "https://vuldb.com/?ctiid.314836"
            },
            {
              "name": "Submit #600881 | Intelbras InControl 2.21.60.9 CSV Injection",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/?submit.600881"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2025-07-04T00:00:00.000Z",
              "value": "Advisory disclosed"
            },
            {
              "lang": "en",
              "time": "2025-07-04T02:00:00.000Z",
              "value": "VulDB entry created"
            },
            {
              "lang": "en",
              "time": "2025-07-04T08:06:48.000Z",
              "value": "VulDB entry last update"
            }
          ],
          "title": "Intelbras InControl operador csv injection"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "assignerShortName": "VulDB",
        "cveId": "CVE-2025-7061",
        "datePublished": "2025-07-04T12:32:04.865Z",
        "dateReserved": "2025-07-04T06:01:33.147Z",
        "dateUpdated": "2025-07-07T16:23:17.934Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2025-6765 (GCVE-0-2025-6765)

    Vulnerability from cvelistv5 – Published: 2025-06-27 12:00 – Updated: 2025-06-27 13:00
    VLAI
    Title
    Intelbras InControl HTTP PUT Request operador permission
    Summary
    A vulnerability, which was classified as critical, has been found in Intelbras InControl 2.21.60.9. This issue affects some unknown processing of the file /v1/operador/ of the component HTTP PUT Request Handler. The manipulation leads to permission issues. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-06-27 12:59 UTC
    CWE
    • CWE-275 - Permission Issues
    • CWE-266 - Incorrect Privilege Assignment
    References
    URL Tags
    https://vuldb.com/?id.314075 vdb-entry
    https://vuldb.com/?ctiid.314075 signaturepermissions-required
    https://vuldb.com/?submit.599873 third-party-advisory
    https://vuldb.com/?submit.599880 third-party-advisory
    Impacted products
    Vendor Product Version
    Intelbras InControl Affected: 2.21.60.9
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-6765",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-06-27T12:59:57.761608Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-06-27T13:00:14.193Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://vuldb.com/?submit.599873"
              },
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://vuldb.com/?submit.599880"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "modules": [
                "HTTP PUT Request Handler"
              ],
              "product": "InControl",
              "vendor": "Intelbras",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.21.60.9"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "lorenzomoulin (VulDB User)"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A vulnerability, which was classified as critical, has been found in Intelbras InControl 2.21.60.9. This issue affects some unknown processing of the file /v1/operador/ of the component HTTP PUT Request Handler. The manipulation leads to permission issues. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way."
            },
            {
              "lang": "de",
              "value": "Eine Schwachstelle wurde in Intelbras InControl 2.21.60.9 entdeckt. Sie wurde als kritisch eingestuft. Davon betroffen ist unbekannter Code der Datei /v1/operador/ der Komponente HTTP PUT Request Handler. Durch die Manipulation mit unbekannten Daten kann eine permission issues-Schwachstelle ausgenutzt werden. Der Angriff kann \u00fcber das Netzwerk erfolgen. Der Exploit steht zur \u00f6ffentlichen Verf\u00fcgung."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
                "version": "4.0"
              }
            },
            {
              "cvssV3_1": {
                "baseScore": 6.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
                "version": "3.1"
              }
            },
            {
              "cvssV3_0": {
                "baseScore": 6.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
                "version": "3.0"
              }
            },
            {
              "cvssV2_0": {
                "baseScore": 6.5,
                "vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR",
                "version": "2.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-275",
                  "description": "Permission Issues",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-266",
                  "description": "Incorrect Privilege Assignment",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-06-27T12:00:15.432Z",
            "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
            "shortName": "VulDB"
          },
          "references": [
            {
              "name": "VDB-314075 | Intelbras InControl HTTP PUT Request operador permission",
              "tags": [
                "vdb-entry"
              ],
              "url": "https://vuldb.com/?id.314075"
            },
            {
              "name": "VDB-314075 | CTI Indicators (IOB, IOC, TTP, IOA)",
              "tags": [
                "signature",
                "permissions-required"
              ],
              "url": "https://vuldb.com/?ctiid.314075"
            },
            {
              "name": "Submit #599873 | Intelbras InControl 2.21.60.9 Improper Handling of Insufficient Permissions or Privileges",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/?submit.599873"
            },
            {
              "name": "Submit #599880 | Intelbras InControl  2.21.60.9 IDOR (Duplicate)",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/?submit.599880"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2025-06-27T00:00:00.000Z",
              "value": "Advisory disclosed"
            },
            {
              "lang": "en",
              "time": "2025-06-27T02:00:00.000Z",
              "value": "VulDB entry created"
            },
            {
              "lang": "en",
              "time": "2025-06-27T07:53:54.000Z",
              "value": "VulDB entry last update"
            }
          ],
          "title": "Intelbras InControl HTTP PUT Request operador permission"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "assignerShortName": "VulDB",
        "cveId": "CVE-2025-6765",
        "datePublished": "2025-06-27T12:00:15.432Z",
        "dateReserved": "2025-06-27T05:48:40.764Z",
        "dateUpdated": "2025-06-27T13:00:14.193Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2025-4996 (GCVE-0-2025-4996)

    Vulnerability from cvelistv5 – Published: 2025-05-20 19:00 – Updated: 2025-05-20 19:29
    VLAI
    Title
    Intelbras RF 301K Add Static IP cross site scripting
    Summary
    A vulnerability, which was classified as problematic, has been found in Intelbras RF 301K 1.1.5. This issue affects some unknown processing of the component Add Static IP. The manipulation of the argument Description leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-05-20 19:29 UTC
    CWE
    References
    URL Tags
    https://vuldb.com/?id.309647 vdb-entrytechnical-description
    https://vuldb.com/?ctiid.309647 signaturepermissions-required
    https://vuldb.com/?submit.501900 third-party-advisory
    Impacted products
    Vendor Product Version
    Intelbras RF 301K Affected: 1.1.5
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-4996",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-05-20T19:29:44.861317Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-05-20T19:29:56.525Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "modules": [
                "Add Static IP"
              ],
              "product": "RF 301K",
              "vendor": "Intelbras",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.1.5"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "Havook (VulDB User)"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A vulnerability, which was classified as problematic, has been found in Intelbras RF 301K 1.1.5. This issue affects some unknown processing of the component Add Static IP. The manipulation of the argument Description leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure."
            },
            {
              "lang": "de",
              "value": "Eine Schwachstelle wurde in Intelbras RF 301K 1.1.5 entdeckt. Sie wurde als problematisch eingestuft. Dies betrifft einen unbekannten Teil der Komponente Add Static IP. Durch Manipulieren des Arguments Description mit unbekannten Daten kann eine cross site scripting-Schwachstelle ausgenutzt werden. Der Angriff kann \u00fcber das Netzwerk passieren. Der Exploit steht zur \u00f6ffentlichen Verf\u00fcgung."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 4.8,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0"
              }
            },
            {
              "cvssV3_1": {
                "baseScore": 2.4,
                "baseSeverity": "LOW",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N",
                "version": "3.1"
              }
            },
            {
              "cvssV3_0": {
                "baseScore": 2.4,
                "baseSeverity": "LOW",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N",
                "version": "3.0"
              }
            },
            {
              "cvssV2_0": {
                "baseScore": 3.3,
                "vectorString": "AV:N/AC:L/Au:M/C:N/I:P/A:N",
                "version": "2.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-79",
                  "description": "Cross Site Scripting",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-94",
                  "description": "Code Injection",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-05-20T19:00:09.160Z",
            "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
            "shortName": "VulDB"
          },
          "references": [
            {
              "name": "VDB-309647 | Intelbras RF 301K Add Static IP cross site scripting",
              "tags": [
                "vdb-entry",
                "technical-description"
              ],
              "url": "https://vuldb.com/?id.309647"
            },
            {
              "name": "VDB-309647 | CTI Indicators (IOB, IOC, TTP, IOA)",
              "tags": [
                "signature",
                "permissions-required"
              ],
              "url": "https://vuldb.com/?ctiid.309647"
            },
            {
              "name": "Submit #501900 | INTELBRAS RF 301K 1.1.5 Cross Site Scripting",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/?submit.501900"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2025-05-20T00:00:00.000Z",
              "value": "Advisory disclosed"
            },
            {
              "lang": "en",
              "time": "2025-05-20T02:00:00.000Z",
              "value": "VulDB entry created"
            },
            {
              "lang": "en",
              "time": "2025-05-20T14:58:41.000Z",
              "value": "VulDB entry last update"
            }
          ],
          "title": "Intelbras RF 301K Add Static IP cross site scripting"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "assignerShortName": "VulDB",
        "cveId": "CVE-2025-4996",
        "datePublished": "2025-05-20T19:00:09.160Z",
        "dateReserved": "2025-05-20T12:53:31.524Z",
        "dateUpdated": "2025-05-20T19:29:56.525Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2025-4286 (GCVE-0-2025-4286)

    Vulnerability from cvelistv5 – Published: 2025-05-05 19:31 – Updated: 2025-05-05 20:05
    VLAI
    Title
    Intelbras InControl Dispositivos Edição Page credentials storage
    Summary
    A vulnerability was found in Intelbras InControl up to 2.21.59. It has been classified as problematic. Affected is an unknown function of the component Dispositivos Edição Page. The manipulation of the argument Senha de Comunicação leads to unprotected storage of credentials. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. According to the vendor this issue should be fixed in a later release.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-05-05 20:05 UTC
    CWE
    • CWE-256 - Unprotected Storage of Credentials
    • CWE-255 - Credentials Management
    References
    URL Tags
    https://vuldb.com/?id.307392 vdb-entrytechnical-description
    https://vuldb.com/?ctiid.307392 signaturepermissions-required
    https://vuldb.com/?submit.483834 third-party-advisory
    https://eldruin.notion.site/Intelbras-InControl-v… exploit
    Impacted products
    Vendor Product Version
    Intelbras InControl Affected: 2.21.0
    Affected: 2.21.1
    Affected: 2.21.2
    Affected: 2.21.3
    Affected: 2.21.4
    Affected: 2.21.5
    Affected: 2.21.6
    Affected: 2.21.7
    Affected: 2.21.8
    Affected: 2.21.9
    Affected: 2.21.10
    Affected: 2.21.11
    Affected: 2.21.12
    Affected: 2.21.13
    Affected: 2.21.14
    Affected: 2.21.15
    Affected: 2.21.16
    Affected: 2.21.17
    Affected: 2.21.18
    Affected: 2.21.19
    Affected: 2.21.20
    Affected: 2.21.21
    Affected: 2.21.22
    Affected: 2.21.23
    Affected: 2.21.24
    Affected: 2.21.25
    Affected: 2.21.26
    Affected: 2.21.27
    Affected: 2.21.28
    Affected: 2.21.29
    Affected: 2.21.30
    Affected: 2.21.31
    Affected: 2.21.32
    Affected: 2.21.33
    Affected: 2.21.34
    Affected: 2.21.35
    Affected: 2.21.36
    Affected: 2.21.37
    Affected: 2.21.38
    Affected: 2.21.39
    Affected: 2.21.40
    Affected: 2.21.41
    Affected: 2.21.42
    Affected: 2.21.43
    Affected: 2.21.44
    Affected: 2.21.45
    Affected: 2.21.46
    Affected: 2.21.47
    Affected: 2.21.48
    Affected: 2.21.49
    Affected: 2.21.50
    Affected: 2.21.51
    Affected: 2.21.52
    Affected: 2.21.53
    Affected: 2.21.54
    Affected: 2.21.55
    Affected: 2.21.56
    Affected: 2.21.57
    Affected: 2.21.58
    Affected: 2.21.59
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-4286",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-05-05T20:05:08.952078Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-05-05T20:05:12.475Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "modules": [
                "Dispositivos Edi\u00e7\u00e3o Page"
              ],
              "product": "InControl",
              "vendor": "Intelbras",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.21.0"
                },
                {
                  "status": "affected",
                  "version": "2.21.1"
                },
                {
                  "status": "affected",
                  "version": "2.21.2"
                },
                {
                  "status": "affected",
                  "version": "2.21.3"
                },
                {
                  "status": "affected",
                  "version": "2.21.4"
                },
                {
                  "status": "affected",
                  "version": "2.21.5"
                },
                {
                  "status": "affected",
                  "version": "2.21.6"
                },
                {
                  "status": "affected",
                  "version": "2.21.7"
                },
                {
                  "status": "affected",
                  "version": "2.21.8"
                },
                {
                  "status": "affected",
                  "version": "2.21.9"
                },
                {
                  "status": "affected",
                  "version": "2.21.10"
                },
                {
                  "status": "affected",
                  "version": "2.21.11"
                },
                {
                  "status": "affected",
                  "version": "2.21.12"
                },
                {
                  "status": "affected",
                  "version": "2.21.13"
                },
                {
                  "status": "affected",
                  "version": "2.21.14"
                },
                {
                  "status": "affected",
                  "version": "2.21.15"
                },
                {
                  "status": "affected",
                  "version": "2.21.16"
                },
                {
                  "status": "affected",
                  "version": "2.21.17"
                },
                {
                  "status": "affected",
                  "version": "2.21.18"
                },
                {
                  "status": "affected",
                  "version": "2.21.19"
                },
                {
                  "status": "affected",
                  "version": "2.21.20"
                },
                {
                  "status": "affected",
                  "version": "2.21.21"
                },
                {
                  "status": "affected",
                  "version": "2.21.22"
                },
                {
                  "status": "affected",
                  "version": "2.21.23"
                },
                {
                  "status": "affected",
                  "version": "2.21.24"
                },
                {
                  "status": "affected",
                  "version": "2.21.25"
                },
                {
                  "status": "affected",
                  "version": "2.21.26"
                },
                {
                  "status": "affected",
                  "version": "2.21.27"
                },
                {
                  "status": "affected",
                  "version": "2.21.28"
                },
                {
                  "status": "affected",
                  "version": "2.21.29"
                },
                {
                  "status": "affected",
                  "version": "2.21.30"
                },
                {
                  "status": "affected",
                  "version": "2.21.31"
                },
                {
                  "status": "affected",
                  "version": "2.21.32"
                },
                {
                  "status": "affected",
                  "version": "2.21.33"
                },
                {
                  "status": "affected",
                  "version": "2.21.34"
                },
                {
                  "status": "affected",
                  "version": "2.21.35"
                },
                {
                  "status": "affected",
                  "version": "2.21.36"
                },
                {
                  "status": "affected",
                  "version": "2.21.37"
                },
                {
                  "status": "affected",
                  "version": "2.21.38"
                },
                {
                  "status": "affected",
                  "version": "2.21.39"
                },
                {
                  "status": "affected",
                  "version": "2.21.40"
                },
                {
                  "status": "affected",
                  "version": "2.21.41"
                },
                {
                  "status": "affected",
                  "version": "2.21.42"
                },
                {
                  "status": "affected",
                  "version": "2.21.43"
                },
                {
                  "status": "affected",
                  "version": "2.21.44"
                },
                {
                  "status": "affected",
                  "version": "2.21.45"
                },
                {
                  "status": "affected",
                  "version": "2.21.46"
                },
                {
                  "status": "affected",
                  "version": "2.21.47"
                },
                {
                  "status": "affected",
                  "version": "2.21.48"
                },
                {
                  "status": "affected",
                  "version": "2.21.49"
                },
                {
                  "status": "affected",
                  "version": "2.21.50"
                },
                {
                  "status": "affected",
                  "version": "2.21.51"
                },
                {
                  "status": "affected",
                  "version": "2.21.52"
                },
                {
                  "status": "affected",
                  "version": "2.21.53"
                },
                {
                  "status": "affected",
                  "version": "2.21.54"
                },
                {
                  "status": "affected",
                  "version": "2.21.55"
                },
                {
                  "status": "affected",
                  "version": "2.21.56"
                },
                {
                  "status": "affected",
                  "version": "2.21.57"
                },
                {
                  "status": "affected",
                  "version": "2.21.58"
                },
                {
                  "status": "affected",
                  "version": "2.21.59"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "eldruin (VulDB User)"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A vulnerability was found in Intelbras InControl up to 2.21.59. It has been classified as problematic. Affected is an unknown function of the component Dispositivos Edi\u00e7\u00e3o Page. The manipulation of the argument Senha de Comunica\u00e7\u00e3o leads to unprotected storage of credentials. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. According to the vendor this issue should be fixed in a later release."
            },
            {
              "lang": "de",
              "value": "Es wurde eine problematische Schwachstelle in Intelbras InControl bis 2.21.59 ausgemacht. Es geht dabei um eine nicht klar definierte Funktion der Komponente Dispositivos Edi\u00e7\u00e3o Page. Durch Manipulieren des Arguments Senha de Comunica\u00e7\u00e3o mit unbekannten Daten kann eine unprotected storage of credentials-Schwachstelle ausgenutzt werden. Der Angriff kann \u00fcber das Netzwerk passieren. Der Exploit steht zur \u00f6ffentlichen Verf\u00fcgung."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 5.1,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0"
              }
            },
            {
              "cvssV3_1": {
                "baseScore": 2.7,
                "baseSeverity": "LOW",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N",
                "version": "3.1"
              }
            },
            {
              "cvssV3_0": {
                "baseScore": 2.7,
                "baseSeverity": "LOW",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N",
                "version": "3.0"
              }
            },
            {
              "cvssV2_0": {
                "baseScore": 3.3,
                "vectorString": "AV:N/AC:L/Au:M/C:P/I:N/A:N",
                "version": "2.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-256",
                  "description": "Unprotected Storage of Credentials",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-255",
                  "description": "Credentials Management",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-05-05T19:31:04.865Z",
            "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
            "shortName": "VulDB"
          },
          "references": [
            {
              "name": "VDB-307392 | Intelbras InControl Dispositivos Edi\u00e7\u00e3o Page credentials storage",
              "tags": [
                "vdb-entry",
                "technical-description"
              ],
              "url": "https://vuldb.com/?id.307392"
            },
            {
              "name": "VDB-307392 | CTI Indicators (IOB, IOC, TTP, IOA)",
              "tags": [
                "signature",
                "permissions-required"
              ],
              "url": "https://vuldb.com/?ctiid.307392"
            },
            {
              "name": "Submit #483834 | Intelbras InControl 2.21.57 Insecure Storage of Sensitive Information",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/?submit.483834"
            },
            {
              "tags": [
                "exploit"
              ],
              "url": "https://eldruin.notion.site/Intelbras-InControl-v2-21-57-Storing-password-in-insecure-format-17d27474cccb8003b647ea832186b162?pvs=4"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2025-05-05T00:00:00.000Z",
              "value": "Advisory disclosed"
            },
            {
              "lang": "en",
              "time": "2025-05-05T02:00:00.000Z",
              "value": "VulDB entry created"
            },
            {
              "lang": "en",
              "time": "2025-05-05T13:51:11.000Z",
              "value": "VulDB entry last update"
            }
          ],
          "title": "Intelbras InControl Dispositivos Edi\u00e7\u00e3o Page credentials storage"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "assignerShortName": "VulDB",
        "cveId": "CVE-2025-4286",
        "datePublished": "2025-05-05T19:31:04.865Z",
        "dateReserved": "2025-05-05T11:46:08.317Z",
        "dateUpdated": "2025-05-05T20:05:12.475Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2025-3157 (GCVE-0-2025-3157)

    Vulnerability from cvelistv5 – Published: 2025-04-03 13:31 – Updated: 2025-04-03 15:41
    VLAI
    Title
    Intelbras WRN 150 Wireless Menu cross site scripting
    Summary
    A vulnerability was found in Intelbras WRN 150 1.0.15_pt_ITB01. It has been rated as problematic. This issue affects some unknown processing of the component Wireless Menu. The manipulation of the argument SSID leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. It is recommended to upgrade the affected component. The vendor was contacted early about this issue and explains that the latest version is not affected.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-04-03 15:37 UTC
    CWE
    References
    URL Tags
    https://vuldb.com/?id.303101 vdb-entrytechnical-description
    https://vuldb.com/?ctiid.303101 signaturepermissions-required
    https://vuldb.com/?submit.501902 third-party-advisory
    Impacted products
    Vendor Product Version
    Intelbras WRN 150 Affected: 1.0.15_pt_ITB01
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-3157",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-04-03T15:37:37.202340Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-04-03T15:41:39.365Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "modules": [
                "Wireless Menu"
              ],
              "product": "WRN 150",
              "vendor": "Intelbras",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.0.15_pt_ITB01"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "Fergod (VulDB User)"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A vulnerability was found in Intelbras WRN 150 1.0.15_pt_ITB01. It has been rated as problematic. This issue affects some unknown processing of the component Wireless Menu. The manipulation of the argument SSID leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. It is recommended to upgrade the affected component. The vendor was contacted early about this issue and explains that the latest version is not affected."
            },
            {
              "lang": "de",
              "value": "Eine Schwachstelle wurde in Intelbras WRN 150 1.0.15_pt_ITB01 ausgemacht. Sie wurde als problematisch eingestuft. Es geht hierbei um eine nicht n\u00e4her spezifizierte Funktion der Komponente Wireless Menu. Durch das Manipulieren des Arguments SSID mit unbekannten Daten kann eine cross site scripting-Schwachstelle ausgenutzt werden. Der Angriff kann \u00fcber das Netzwerk angegangen werden. Der Exploit steht zur \u00f6ffentlichen Verf\u00fcgung. Als bestm\u00f6gliche Massnahme wird das Einspielen eines Upgrades empfohlen."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 4.8,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0"
              }
            },
            {
              "cvssV3_1": {
                "baseScore": 2.4,
                "baseSeverity": "LOW",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N",
                "version": "3.1"
              }
            },
            {
              "cvssV3_0": {
                "baseScore": 2.4,
                "baseSeverity": "LOW",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N",
                "version": "3.0"
              }
            },
            {
              "cvssV2_0": {
                "baseScore": 3.3,
                "vectorString": "AV:N/AC:L/Au:M/C:N/I:P/A:N",
                "version": "2.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-79",
                  "description": "Cross Site Scripting",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-94",
                  "description": "Code Injection",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-04-03T13:31:04.529Z",
            "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
            "shortName": "VulDB"
          },
          "references": [
            {
              "name": "VDB-303101 | Intelbras WRN 150 Wireless Menu cross site scripting",
              "tags": [
                "vdb-entry",
                "technical-description"
              ],
              "url": "https://vuldb.com/?id.303101"
            },
            {
              "name": "VDB-303101 | CTI Indicators (IOB, IOC, TTP, IOA)",
              "tags": [
                "signature",
                "permissions-required"
              ],
              "url": "https://vuldb.com/?ctiid.303101"
            },
            {
              "name": "Submit #501902 | Intelbras WRN 150 V1.0.15_pt_ITB01 Cross Site Scripting",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/?submit.501902"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2025-04-03T00:00:00.000Z",
              "value": "Advisory disclosed"
            },
            {
              "lang": "en",
              "time": "2025-04-03T02:00:00.000Z",
              "value": "VulDB entry created"
            },
            {
              "lang": "en",
              "time": "2025-04-03T08:05:15.000Z",
              "value": "VulDB entry last update"
            }
          ],
          "title": "Intelbras WRN 150 Wireless Menu cross site scripting"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "assignerShortName": "VulDB",
        "cveId": "CVE-2025-3157",
        "datePublished": "2025-04-03T13:31:04.529Z",
        "dateReserved": "2025-04-03T05:59:48.128Z",
        "dateUpdated": "2025-04-03T15:41:39.365Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2025-0784 (GCVE-0-2025-0784)

    Vulnerability from cvelistv5 – Published: 2025-01-28 20:00 – Updated: 2025-02-12 20:01
    VLAI
    Title
    Intelbras InControl Registered User usuario cleartext transmission
    Summary
    A vulnerability has been found in Intelbras InControl up to 2.21.58 and classified as problematic. This vulnerability affects unknown code of the file /v1/usuario/ of the component Registered User Handler. The manipulation leads to cleartext transmission of sensitive information. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. Upgrading to version 2.21.59 is able to address this issue. It is recommended to upgrade the affected component.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-01-28 20:32 UTC
    CWE
    • CWE-319 - Cleartext Transmission of Sensitive Information
    • CWE-310 - Cryptographic Issues
    References
    Impacted products
    Vendor Product Version
    Intelbras InControl Affected: 2.21.0
    Affected: 2.21.1
    Affected: 2.21.2
    Affected: 2.21.3
    Affected: 2.21.4
    Affected: 2.21.5
    Affected: 2.21.6
    Affected: 2.21.7
    Affected: 2.21.8
    Affected: 2.21.9
    Affected: 2.21.10
    Affected: 2.21.11
    Affected: 2.21.12
    Affected: 2.21.13
    Affected: 2.21.14
    Affected: 2.21.15
    Affected: 2.21.16
    Affected: 2.21.17
    Affected: 2.21.18
    Affected: 2.21.19
    Affected: 2.21.20
    Affected: 2.21.21
    Affected: 2.21.22
    Affected: 2.21.23
    Affected: 2.21.24
    Affected: 2.21.25
    Affected: 2.21.26
    Affected: 2.21.27
    Affected: 2.21.28
    Affected: 2.21.29
    Affected: 2.21.30
    Affected: 2.21.31
    Affected: 2.21.32
    Affected: 2.21.33
    Affected: 2.21.34
    Affected: 2.21.35
    Affected: 2.21.36
    Affected: 2.21.37
    Affected: 2.21.38
    Affected: 2.21.39
    Affected: 2.21.40
    Affected: 2.21.41
    Affected: 2.21.42
    Affected: 2.21.43
    Affected: 2.21.44
    Affected: 2.21.45
    Affected: 2.21.46
    Affected: 2.21.47
    Affected: 2.21.48
    Affected: 2.21.49
    Affected: 2.21.50
    Affected: 2.21.51
    Affected: 2.21.52
    Affected: 2.21.53
    Affected: 2.21.54
    Affected: 2.21.55
    Affected: 2.21.56
    Affected: 2.21.57
    Affected: 2.21.58
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-0784",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-01-28T20:32:08.923755Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-02-12T20:01:10.799Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "modules": [
                "Registered User Handler"
              ],
              "product": "InControl",
              "vendor": "Intelbras",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.21.0"
                },
                {
                  "status": "affected",
                  "version": "2.21.1"
                },
                {
                  "status": "affected",
                  "version": "2.21.2"
                },
                {
                  "status": "affected",
                  "version": "2.21.3"
                },
                {
                  "status": "affected",
                  "version": "2.21.4"
                },
                {
                  "status": "affected",
                  "version": "2.21.5"
                },
                {
                  "status": "affected",
                  "version": "2.21.6"
                },
                {
                  "status": "affected",
                  "version": "2.21.7"
                },
                {
                  "status": "affected",
                  "version": "2.21.8"
                },
                {
                  "status": "affected",
                  "version": "2.21.9"
                },
                {
                  "status": "affected",
                  "version": "2.21.10"
                },
                {
                  "status": "affected",
                  "version": "2.21.11"
                },
                {
                  "status": "affected",
                  "version": "2.21.12"
                },
                {
                  "status": "affected",
                  "version": "2.21.13"
                },
                {
                  "status": "affected",
                  "version": "2.21.14"
                },
                {
                  "status": "affected",
                  "version": "2.21.15"
                },
                {
                  "status": "affected",
                  "version": "2.21.16"
                },
                {
                  "status": "affected",
                  "version": "2.21.17"
                },
                {
                  "status": "affected",
                  "version": "2.21.18"
                },
                {
                  "status": "affected",
                  "version": "2.21.19"
                },
                {
                  "status": "affected",
                  "version": "2.21.20"
                },
                {
                  "status": "affected",
                  "version": "2.21.21"
                },
                {
                  "status": "affected",
                  "version": "2.21.22"
                },
                {
                  "status": "affected",
                  "version": "2.21.23"
                },
                {
                  "status": "affected",
                  "version": "2.21.24"
                },
                {
                  "status": "affected",
                  "version": "2.21.25"
                },
                {
                  "status": "affected",
                  "version": "2.21.26"
                },
                {
                  "status": "affected",
                  "version": "2.21.27"
                },
                {
                  "status": "affected",
                  "version": "2.21.28"
                },
                {
                  "status": "affected",
                  "version": "2.21.29"
                },
                {
                  "status": "affected",
                  "version": "2.21.30"
                },
                {
                  "status": "affected",
                  "version": "2.21.31"
                },
                {
                  "status": "affected",
                  "version": "2.21.32"
                },
                {
                  "status": "affected",
                  "version": "2.21.33"
                },
                {
                  "status": "affected",
                  "version": "2.21.34"
                },
                {
                  "status": "affected",
                  "version": "2.21.35"
                },
                {
                  "status": "affected",
                  "version": "2.21.36"
                },
                {
                  "status": "affected",
                  "version": "2.21.37"
                },
                {
                  "status": "affected",
                  "version": "2.21.38"
                },
                {
                  "status": "affected",
                  "version": "2.21.39"
                },
                {
                  "status": "affected",
                  "version": "2.21.40"
                },
                {
                  "status": "affected",
                  "version": "2.21.41"
                },
                {
                  "status": "affected",
                  "version": "2.21.42"
                },
                {
                  "status": "affected",
                  "version": "2.21.43"
                },
                {
                  "status": "affected",
                  "version": "2.21.44"
                },
                {
                  "status": "affected",
                  "version": "2.21.45"
                },
                {
                  "status": "affected",
                  "version": "2.21.46"
                },
                {
                  "status": "affected",
                  "version": "2.21.47"
                },
                {
                  "status": "affected",
                  "version": "2.21.48"
                },
                {
                  "status": "affected",
                  "version": "2.21.49"
                },
                {
                  "status": "affected",
                  "version": "2.21.50"
                },
                {
                  "status": "affected",
                  "version": "2.21.51"
                },
                {
                  "status": "affected",
                  "version": "2.21.52"
                },
                {
                  "status": "affected",
                  "version": "2.21.53"
                },
                {
                  "status": "affected",
                  "version": "2.21.54"
                },
                {
                  "status": "affected",
                  "version": "2.21.55"
                },
                {
                  "status": "affected",
                  "version": "2.21.56"
                },
                {
                  "status": "affected",
                  "version": "2.21.57"
                },
                {
                  "status": "affected",
                  "version": "2.21.58"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "eldruin (VulDB User)"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A vulnerability has been found in Intelbras InControl up to 2.21.58 and classified as problematic. This vulnerability affects unknown code of the file /v1/usuario/ of the component Registered User Handler. The manipulation leads to cleartext transmission of sensitive information. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. Upgrading to version 2.21.59 is able to address this issue. It is recommended to upgrade the affected component."
            },
            {
              "lang": "de",
              "value": "In Intelbras InControl bis 2.21.58 wurde eine problematische Schwachstelle gefunden. Dabei geht es um eine nicht genauer bekannte Funktion der Datei /v1/usuario/ der Komponente Registered User Handler. Durch Beeinflussen mit unbekannten Daten kann eine cleartext transmission of sensitive information-Schwachstelle ausgenutzt werden. Die Umsetzung des Angriffs kann dabei \u00fcber das Netzwerk erfolgen. Die Komplexit\u00e4t eines Angriffs ist eher hoch. Das Ausnutzen gilt als schwierig. Der Exploit steht zur \u00f6ffentlichen Verf\u00fcgung. Ein Aktualisieren auf die Version 2.21.59 vermag dieses Problem zu l\u00f6sen. Als bestm\u00f6gliche Massnahme wird das Einspielen eines Upgrades empfohlen."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 6.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0"
              }
            },
            {
              "cvssV3_1": {
                "baseScore": 3.7,
                "baseSeverity": "LOW",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
                "version": "3.1"
              }
            },
            {
              "cvssV3_0": {
                "baseScore": 3.7,
                "baseSeverity": "LOW",
                "vectorString": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
                "version": "3.0"
              }
            },
            {
              "cvssV2_0": {
                "baseScore": 2.6,
                "vectorString": "AV:N/AC:H/Au:N/C:P/I:N/A:N",
                "version": "2.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-319",
                  "description": "Cleartext Transmission of Sensitive Information",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-310",
                  "description": "Cryptographic Issues",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-01-28T20:00:13.220Z",
            "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
            "shortName": "VulDB"
          },
          "references": [
            {
              "name": "VDB-293908 | Intelbras InControl Registered User usuario cleartext transmission",
              "tags": [
                "vdb-entry"
              ],
              "url": "https://vuldb.com/?id.293908"
            },
            {
              "name": "VDB-293908 | CTI Indicators (IOB, IOC, TTP, IOA)",
              "tags": [
                "signature",
                "permissions-required"
              ],
              "url": "https://vuldb.com/?ctiid.293908"
            },
            {
              "name": "Submit #483835 | Intelbras InControl 2.21.57 Cleartext Transmission of Sensitive Information",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/?submit.483835"
            },
            {
              "tags": [
                "exploit"
              ],
              "url": "https://eldruin.notion.site/Intelbras-InControl-v2-21-57-Password-exposed-in-clear-text-17d27474cccb806fba1efda195c78258?pvs=4"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2025-01-28T00:00:00.000Z",
              "value": "Advisory disclosed"
            },
            {
              "lang": "en",
              "time": "2025-01-28T01:00:00.000Z",
              "value": "VulDB entry created"
            },
            {
              "lang": "en",
              "time": "2025-01-28T15:05:34.000Z",
              "value": "VulDB entry last update"
            }
          ],
          "title": "Intelbras InControl Registered User usuario cleartext transmission"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "assignerShortName": "VulDB",
        "cveId": "CVE-2025-0784",
        "datePublished": "2025-01-28T20:00:13.220Z",
        "dateReserved": "2025-01-28T13:59:47.508Z",
        "dateUpdated": "2025-02-12T20:01:10.799Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-12897 (GCVE-0-2024-12897)

    Vulnerability from cvelistv5 – Published: 2024-12-22 23:31 – Updated: 2024-12-27 08:51 Unsupported When Assigned
    VLAI
    Title
    Intelbras VIP S4320 G2 Web Interface Sha1Account1 path traversal
    Summary
    A vulnerability was found in Intelbras VIP S3020 G2, VIP S4020 G2, VIP S4020 G3 and VIP S4320 G2 up to 20241222. It has been classified as critical. This affects an unknown part of the file ../mtd/Config/Sha1Account1 of the component Web Interface. The manipulation leads to path traversal: '../filedir'. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-12-24 16:00 UTC
    CWE
    • CWE-24 - Path Traversal: '../filedir'
    • CWE-23 - Relative Path Traversal
    References
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-12897",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-12-24T16:00:18.160289Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-12-24T16:00:32.149Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://netsecfish.notion.site/Path-Traversal-Vulnerability-in-IntelBras-IP-Cameras-mtd-Config-Sha1Account1-and-mtd-Confi-15e6b683e67c80809442ee3425f753b7"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "modules": [
                "Web Interface"
              ],
              "product": "VIP S3020 G2",
              "vendor": "Intelbras",
              "versions": [
                {
                  "status": "affected",
                  "version": "20241222"
                }
              ]
            },
            {
              "modules": [
                "Web Interface"
              ],
              "product": "VIP S4020 G2",
              "vendor": "Intelbras",
              "versions": [
                {
                  "status": "affected",
                  "version": "20241222"
                }
              ]
            },
            {
              "modules": [
                "Web Interface"
              ],
              "product": "VIP S4020 G3",
              "vendor": "Intelbras",
              "versions": [
                {
                  "status": "affected",
                  "version": "20241222"
                }
              ]
            },
            {
              "modules": [
                "Web Interface"
              ],
              "product": "VIP S4320 G2",
              "vendor": "Intelbras",
              "versions": [
                {
                  "status": "affected",
                  "version": "20241222"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "netsecfish (VulDB User)"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A vulnerability was found in Intelbras VIP S3020 G2, VIP S4020 G2, VIP S4020 G3 and VIP S4320 G2 up to 20241222. It has been classified as critical. This affects an unknown part of the file ../mtd/Config/Sha1Account1 of the component Web Interface. The manipulation leads to path traversal: \u0027../filedir\u0027. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used."
            },
            {
              "lang": "de",
              "value": "Es wurde eine Schwachstelle in Intelbras VIP S3020 G2, VIP S4020 G2, VIP S4020 G3 and VIP S4320 G2 bis 20241222 ausgemacht. Sie wurde als kritisch eingestuft. Es geht dabei um eine nicht klar definierte Funktion der Datei ../mtd/Config/Sha1Account1 der Komponente Web Interface. Durch Beeinflussen mit unbekannten Daten kann eine path traversal: \u0027../filedir\u0027-Schwachstelle ausgenutzt werden. Der Angriff kann \u00fcber das Netzwerk passieren. Der Exploit steht zur \u00f6ffentlichen Verf\u00fcgung."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0"
              }
            },
            {
              "cvssV3_1": {
                "baseScore": 4.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
                "version": "3.1"
              }
            },
            {
              "cvssV3_0": {
                "baseScore": 4.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
                "version": "3.0"
              }
            },
            {
              "cvssV2_0": {
                "baseScore": 4,
                "vectorString": "AV:N/AC:L/Au:S/C:P/I:N/A:N",
                "version": "2.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-24",
                  "description": "Path Traversal: \u0027../filedir\u0027",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-23",
                  "description": "Relative Path Traversal",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-12-27T08:51:42.245Z",
            "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
            "shortName": "VulDB"
          },
          "references": [
            {
              "name": "VDB-289167 | Intelbras VIP S4320 G2 Web Interface Sha1Account1 path traversal",
              "tags": [
                "vdb-entry",
                "technical-description"
              ],
              "url": "https://vuldb.com/?id.289167"
            },
            {
              "name": "VDB-289167 | CTI Indicators (IOB, IOC, TTP, IOA)",
              "tags": [
                "signature",
                "permissions-required"
              ],
              "url": "https://vuldb.com/?ctiid.289167"
            },
            {
              "name": "Submit #464260 | IntelBras  IPC-HFW1200S, IPC-HFW2300R-Z, IPC-HFW5220E-Z, IPC-HDW1200S, VIP S3020 G2, VIP S4020 G2, VIP S4320 G2, VIP S4020 G3 WebVersion: 3.2.1.225946; WebVersion: 3.2.1.291804 Path Traversal",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/?submit.464260"
            },
            {
              "tags": [
                "exploit"
              ],
              "url": "https://netsecfish.notion.site/Path-Traversal-Vulnerability-in-IntelBras-IP-Cameras-mtd-Config-Sha1Account1-and-mtd-Confi-15e6b683e67c80809442ee3425f753b7?pvs=4"
            }
          ],
          "tags": [
            "unsupported-when-assigned"
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2024-12-22T00:00:00.000Z",
              "value": "Advisory disclosed"
            },
            {
              "lang": "en",
              "time": "2024-12-22T01:00:00.000Z",
              "value": "VulDB entry created"
            },
            {
              "lang": "en",
              "time": "2024-12-27T09:56:32.000Z",
              "value": "VulDB entry last update"
            }
          ],
          "title": "Intelbras VIP S4320 G2 Web Interface Sha1Account1 path traversal"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "assignerShortName": "VulDB",
        "cveId": "CVE-2024-12897",
        "datePublished": "2024-12-22T23:31:05.102Z",
        "dateReserved": "2024-12-22T08:47:43.200Z",
        "dateUpdated": "2024-12-27T08:51:42.245Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-12896 (GCVE-0-2024-12896)

    Vulnerability from cvelistv5 – Published: 2024-12-22 23:00 – Updated: 2024-12-24 16:07 Unsupported When Assigned
    VLAI
    Title
    Intelbras VIP S4320 G2 Web Interface webCapsConfig information disclosure
    Summary
    A vulnerability was found in Intelbras VIP S3020 G2, VIP S4020 G2, VIP S4020 G3 and VIP S4320 G2 up to 20241222 and classified as problematic. Affected by this issue is some unknown functionality of the file /web_caps/webCapsConfig of the component Web Interface. The manipulation leads to information disclosure. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor assesses that "the information disclosed in the URL is not sensitive or poses any risk to the user".
    SSVC
    Exploitation: poc Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-12-24 16:07 UTC
    CWE
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-12896",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-12-24T16:07:43.746824Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-12-24T16:07:59.581Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://netsecfish.notion.site/IntelBras-IP-Camera-Information-Disclosure-15e6b683e67c80a89f89daf59daa9ea8"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "modules": [
                "Web Interface"
              ],
              "product": "VIP S3020 G2",
              "vendor": "Intelbras",
              "versions": [
                {
                  "status": "affected",
                  "version": "20241222"
                }
              ]
            },
            {
              "modules": [
                "Web Interface"
              ],
              "product": "VIP S4020 G2",
              "vendor": "Intelbras",
              "versions": [
                {
                  "status": "affected",
                  "version": "20241222"
                }
              ]
            },
            {
              "modules": [
                "Web Interface"
              ],
              "product": "VIP S4020 G3",
              "vendor": "Intelbras",
              "versions": [
                {
                  "status": "affected",
                  "version": "20241222"
                }
              ]
            },
            {
              "modules": [
                "Web Interface"
              ],
              "product": "VIP S4320 G2",
              "vendor": "Intelbras",
              "versions": [
                {
                  "status": "affected",
                  "version": "20241222"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "netsecfish (VulDB User)"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A vulnerability was found in Intelbras VIP S3020 G2, VIP S4020 G2, VIP S4020 G3 and VIP S4320 G2 up to 20241222 and classified as problematic. Affected by this issue is some unknown functionality of the file /web_caps/webCapsConfig of the component Web Interface. The manipulation leads to information disclosure. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor assesses that \"the information disclosed in the URL is not sensitive or poses any risk to the user\"."
            },
            {
              "lang": "de",
              "value": "Eine Schwachstelle wurde in Intelbras VIP S3020 G2, VIP S4020 G2, VIP S4020 G3 and VIP S4320 G2 bis 20241222 gefunden. Sie wurde als problematisch eingestuft. Es geht hierbei um eine nicht n\u00e4her spezifizierte Funktion der Datei /web_caps/webCapsConfig der Komponente Web Interface. Durch das Beeinflussen mit unbekannten Daten kann eine information disclosure-Schwachstelle ausgenutzt werden. Der Angriff kann \u00fcber das Netzwerk angegangen werden. Der Exploit steht zur \u00f6ffentlichen Verf\u00fcgung."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 6.9,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0"
              }
            },
            {
              "cvssV3_1": {
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
                "version": "3.1"
              }
            },
            {
              "cvssV3_0": {
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
                "version": "3.0"
              }
            },
            {
              "cvssV2_0": {
                "baseScore": 5,
                "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
                "version": "2.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-200",
                  "description": "Information Disclosure",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-284",
                  "description": "Improper Access Controls",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-12-22T23:00:12.200Z",
            "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
            "shortName": "VulDB"
          },
          "references": [
            {
              "name": "VDB-289166 | Intelbras VIP S4320 G2 Web Interface webCapsConfig information disclosure",
              "tags": [
                "vdb-entry"
              ],
              "url": "https://vuldb.com/?id.289166"
            },
            {
              "name": "VDB-289166 | CTI Indicators (IOB, IOC, TTP, IOA)",
              "tags": [
                "signature",
                "permissions-required"
              ],
              "url": "https://vuldb.com/?ctiid.289166"
            },
            {
              "name": "Submit #464258 | IntelBras VIP S3020 G2, VIP S4020 G2, VIP S4320 G2, VIP S4020 G3, IPC-HFW1200S, IPC-HFW2300R-Z, IPC-HFW5220E-Z, IPC-HDW1200S N/A Information Disclosure",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/?submit.464258"
            },
            {
              "tags": [
                "exploit"
              ],
              "url": "https://netsecfish.notion.site/IntelBras-IP-Camera-Information-Disclosure-15e6b683e67c80a89f89daf59daa9ea8?pvs=73"
            }
          ],
          "tags": [
            "unsupported-when-assigned"
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2024-12-22T00:00:00.000Z",
              "value": "Advisory disclosed"
            },
            {
              "lang": "en",
              "time": "2024-12-22T01:00:00.000Z",
              "value": "VulDB entry created"
            },
            {
              "lang": "en",
              "time": "2024-12-22T09:53:48.000Z",
              "value": "VulDB entry last update"
            }
          ],
          "title": "Intelbras VIP S4320 G2 Web Interface webCapsConfig information disclosure"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "assignerShortName": "VulDB",
        "cveId": "CVE-2024-12896",
        "datePublished": "2024-12-22T23:00:12.200Z",
        "dateReserved": "2024-12-22T08:47:39.237Z",
        "dateUpdated": "2024-12-24T16:07:59.581Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }