VulnerabilityModified
CVE-2025-26062
An access control issue in Intelbras RX1500 v2.2.9 and RX3000 v1.0.11 allows unauthenticated attackers to access the router's settings file and obtain potentially sensitive information from the current settings.
CRITICAL 9.8EPSS 1.08%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.08%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
An access control issue in Intelbras RX1500 v2.2.9 and RX3000 v1.0.11 allows unauthenticated attackers to access the router's settings file and obtain potentially sensitive information from the current settings.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.08% probability · 63th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-284
- Affected
- intelbras/rx 1500 firmware · intelbras/rx 3000 firmware
- Source
- cve@mitre.org
References
- https://manuais.intelbras.com.br/manual-linha-rx/ChangeLogRX1500.htmlRelease Notes
- https://manuais.intelbras.com.br/manual-linha-rx/ChangeLogRX3000.htmlRelease Notes
- https://seclists.org/fulldisclosure/2025/Jul/14Exploit, Mailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2025/Jul/14
- http://seclists.org/fulldisclosure/2025/Jul/26
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.