CVE-2025-26062

critical

Description

An access control issue in Intelbras RX1500 v2.2.9 and RX3000 v1.0.11 allows unauthenticated attackers to access the router's settings file and obtain potentially sensitive information from the current settings.

References

https://seclists.org/fulldisclosure/2025/Jul/14

https://manuais.intelbras.com.br/manual-linha-rx/ChangeLogRX3000.html

https://manuais.intelbras.com.br/manual-linha-rx/ChangeLogRX1500.html

http://seclists.org/fulldisclosure/2025/Jul/26

http://seclists.org/fulldisclosure/2025/Jul/14

Details

Source: Mitre, NVD

Published: 2025-07-31

Updated: 2025-11-03

Risk Information

CVSS v2

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Severity: Critical

CVSS v3

Base Score: 9.8

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical

EPSS

EPSS: 0.00052