← Vulnerability feed

Vulnerability record · CVE-2025-26062 · published 31 July 2025

CVE-2025-26062: Intelbras rx 1500 firmware improper access control vulnerability

Intelbras · Rx 1500 Firmware

An access control issue in Intelbras RX1500 v2.2.9 and RX3000 v1.0.11 allows unauthenticated attackers to access the router's settings file and obtain potentially sensitive information from the current settings.

9.8 CVSS 3.1 Critical EPSS 1.1% · top 36.2% CWE-284 · Improper access control
9.8CVSS 3.1 base score
1.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
5References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

An access control issue in Intelbras RX1500 v2.2.9 and RX3000 v1.0.11 allows unauthenticated attackers to access the router's settings file and obtain potentially sensitive information from the current settings.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-26062 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-26063Intelbras rx 1500 firmware command injection vulnerabilityAn issue in Intelbras RX1500 v2.2.9 and RX3000 v1.0.11 allows unauthenticated attackers to execute arbitrary code via injecting a crafted payload int…EPSS 1.3%7.3CVE-2025-26065Intelbras rx 1500 firmware cross-site scripting vulnerabilityA cross-site scripting (XSS) vulnerability in Intelbras RX1500 v2.2.9 and RX3000 v1.0.11 allows attackers to execute arbitrary web scripts or HTML vi…EPSS 0.36%7.3CVE-2025-26064Intelbras rx 1500 firmware cross-site scripting vulnerabilityA cross-site scripting (XSS) vulnerability in Intelbras RX1500 v2.2.9 and RX3000 v1.0.11 allows attackers to execute arbitrary web scripts or HTML vi…EPSS 1.0%6.5CVE-2025-50405Intelbras rx 1500 firmware improper access control vulnerabilityIntelbras RX1500 Router v2.2.17 and before is vulnerable to Incorrect Access Control in the FirmwareUpload function and GetFirmwareValidation functio…EPSS 0.33%5.4CVE-2023-6103Intelbras rx 1500 firmware cross-site scripting vulnerabilityA vulnerability has been found in Intelbras RX 1500 1.1.9 and classified as problematic. Affected by this vulnerability is an unknown functionality o…EPSS 0.55%5.3CVE-2025-50404Intelbras rx 1500 firmware integer overflow vulnerabilityIntelbras RX1500 Router v2.2.17 and before is vulnerable to Integer Overflow. The websReadEvent function incorrectly uses the int type when processin…EPSS 8.2%7.8CVE-2026-81963Windows Update Stack link-following privilege escalationWindows Update Stack resolves links improperly before accessing files, a link-following flaw (CWE-59) compounded by improper access control (CWE-284)…KEVEPSS 0.39%analysed10.0CVE-2026-21962Oracle HTTP Server and WebLogic Proxy Plug-in improper access controlOracle HTTP Server and the WebLogic Server Proxy Plug-in (for Apache HTTP Server and IIS) contain an improper access control flaw (CWE-284) in suppor…KEVEPSS 71%analysed

Source: NIST National Vulnerability Database (record CVE-2025-26062), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.