A weakness has been identified in Intelbras InControl 2.21.60.9. This vulnerability affects unknown code of the file /v1/operador/ of the component JSON Endpoint. Executing manipulation can lead to information disclosure. It is possible to launch the attack remotely. A high complexity level is associated with this attack. It is stated that the exploitability is difficult. The exploit has been made available to the public and could be exploited. Upgrading the affected component is advised.
References
| Link | Resource |
|---|---|
| https://backend.intelbras.com/sites/default/files/2025-08/Aviso%20de%20Seguran%C3%A7a%20-%20Incontrol%202.21.60%20e%202.21.61%20PT-IN%20.pdf | |
| https://vuldb.com/?ctiid.318641 | Permissions Required VDB Entry |
| https://vuldb.com/?id.318641 | Third Party Advisory VDB Entry |
| https://vuldb.com/?submit.579544 | Third Party Advisory VDB Entry |
Configurations
History
29 Oct 2025, 07:15
| Type | Values Removed | Values Added |
|---|---|---|
| Summary | (en) A weakness has been identified in Intelbras InControl 2.21.60.9. This vulnerability affects unknown code of the file /v1/operador/ of the component JSON Endpoint. Executing manipulation can lead to information disclosure. It is possible to launch the attack remotely. A high complexity level is associated with this attack. It is stated that the exploitability is difficult. The exploit has been made available to the public and could be exploited. Upgrading the affected component is advised. | |
| References |
|
21 Aug 2025, 00:14
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:intelbras:incontrol_web:2.21.60.9:*:*:*:*:*:*:* | |
| CWE | NVD-CWE-noinfo | |
| First Time |
Intelbras
Intelbras incontrol Web |
|
| References | () https://vuldb.com/?ctiid.318641 - Permissions Required, VDB Entry | |
| References | () https://vuldb.com/?id.318641 - Third Party Advisory, VDB Entry | |
| References | () https://vuldb.com/?submit.579544 - Third Party Advisory, VDB Entry |
04 Aug 2025, 15:06
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
04 Aug 2025, 11:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-08-04 11:15
Updated : 2025-10-29 07:15
NVD link : CVE-2025-8515
Mitre link : CVE-2025-8515
CVE.ORG link : CVE-2025-8515
JSON object : View
Products Affected
intelbras
- incontrol_web
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
CWE-284Improper Access Control
NVD-CWE-noinfo