CVE-2025-26062

An access control issue in Intelbras RX1500 v2.2.9 and RX3000 v1.0.11 allows unauthenticated attackers to access the router's settings file and obtain potentially sensitive information from the current settings.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:intelbras:rx_1500_firmware:2.2.9:*:*:*:*:*:*:*
cpe:2.3:h:intelbras:rx_1500:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:intelbras:rx_3000_firmware:1.0.11:*:*:*:*:*:*:*
cpe:2.3:h:intelbras:rx_3000:-:*:*:*:*:*:*:*

History

12 Sep 2025, 16:52

Type Values Removed Values Added
CPE cpe:2.3:h:intelbras:rx_3000:-:*:*:*:*:*:*:*
cpe:2.3:h:intelbras:rx_1500:-:*:*:*:*:*:*:*
cpe:2.3:o:intelbras:rx_1500_firmware:2.2.9:*:*:*:*:*:*:*
cpe:2.3:o:intelbras:rx_3000_firmware:1.0.11:*:*:*:*:*:*:*
First Time Intelbras rx 1500
Intelbras rx 1500 Firmware
Intelbras rx 3000 Firmware
Intelbras rx 3000
Intelbras
References () https://manuais.intelbras.com.br/manual-linha-rx/ChangeLogRX1500.html - () https://manuais.intelbras.com.br/manual-linha-rx/ChangeLogRX1500.html - Release Notes
References () https://manuais.intelbras.com.br/manual-linha-rx/ChangeLogRX3000.html - () https://manuais.intelbras.com.br/manual-linha-rx/ChangeLogRX3000.html - Release Notes
References () https://seclists.org/fulldisclosure/2025/Jul/14 - () https://seclists.org/fulldisclosure/2025/Jul/14 - Exploit, Mailing List, Third Party Advisory

04 Aug 2025, 15:06

Type Values Removed Values Added
Summary
  • (es) Un problema de control de acceso en Intelbras RX1500 v2.2.9 y RX3000 v1.0.11 permite a atacantes no autenticados acceder al archivo de configuración del enrutador y obtener información potencialmente confidencial de la configuración actual.

31 Jul 2025, 20:15

Type Values Removed Values Added
CWE CWE-284
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

31 Jul 2025, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-31 19:15

Updated : 2025-09-12 16:52


NVD link : CVE-2025-26062

Mitre link : CVE-2025-26062

CVE.ORG link : CVE-2025-26062


JSON object : View

Products Affected

intelbras

  • rx_3000_firmware
  • rx_1500
  • rx_3000
  • rx_1500_firmware
CWE
CWE-284

Improper Access Control