CVE-2026-3101

A vulnerability was found in Intelbras TIP 635G 1.12.3.5. This vulnerability affects unknown code of the component Ping Handler. The manipulation results in os command injection. The attack can be executed remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:intelbras:tip_635g_firmware:1.12.3.5:*:*:*:*:*:*:*
cpe:2.3:h:intelbras:tip_635g:-:*:*:*:*:*:*:*

History

26 Feb 2026, 20:09

Type Values Removed Values Added
First Time Intelbras tip 635g Firmware
Intelbras tip 635g
Intelbras
CPE cpe:2.3:h:intelbras:tip_635g:-:*:*:*:*:*:*:*
cpe:2.3:o:intelbras:tip_635g_firmware:1.12.3.5:*:*:*:*:*:*:*
References () https://vuldb.com/?ctiid.347527 - () https://vuldb.com/?ctiid.347527 - Permissions Required
References () https://vuldb.com/?id.347527 - () https://vuldb.com/?id.347527 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.757986 - () https://vuldb.com/?submit.757986 - Third Party Advisory, VDB Entry
References () https://www.notion.so/eldruin/Intelbras-TIP-635G-Authenticated-OS-Command-Injection-Leading-to-Root-RCE-30627474cccb80929328e7c3b3ea0f9b - () https://www.notion.so/eldruin/Intelbras-TIP-635G-Authenticated-OS-Command-Injection-Leading-to-Root-RCE-30627474cccb80929328e7c3b3ea0f9b - Exploit, Third Party Advisory

24 Feb 2026, 15:21

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-24 15:21

Updated : 2026-02-26 20:09


NVD link : CVE-2026-3101

Mitre link : CVE-2026-3101

CVE.ORG link : CVE-2026-3101


JSON object : View

Products Affected

intelbras

  • tip_635g
  • tip_635g_firmware
CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')