Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-4286


A vulnerability was found in Intelbras InControl up to 2.21.59. It has been classified as problematic. Affected is an unknown function of the component Dispositivos Edição Page. The manipulation of the argument Senha de Comunicação leads to unprotected storage of credentials. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. According to the vendor this issue should be fixed in a later release.


Published

2025-05-05T20:15:21.897

Last Modified

2025-08-20T02:29:45.667

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 2.7 (LOW)

CVSSv2 Vector

AV:N/AC:L/Au:M/C:P/I:N/A:N

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: MULTIPLE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

6.4

Impact Score

2.9

Weaknesses
  • Type: Secondary
    CWE-255
    CWE-256

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application intelbras incontrol_web ≤ 2.21.59 Yes

References