← Vulnerability feed

Vulnerability record · CVE-2025-26063 · published 31 July 2025

CVE-2025-26063: Intelbras rx 1500 firmware command injection vulnerability

Intelbras · Rx 1500 Firmware

An issue in Intelbras RX1500 v2.2.9 and RX3000 v1.0.11 allows unauthenticated attackers to execute arbitrary code via injecting a crafted payload into the ESSID name when creating a network.

9.8 CVSS 3.1 Critical EPSS 1.3% · top 31.3% CWE-77 · Command injection
9.8CVSS 3.1 base score
1.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
5References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

An issue in Intelbras RX1500 v2.2.9 and RX3000 v1.0.11 allows unauthenticated attackers to execute arbitrary code via injecting a crafted payload into the ESSID name when creating a network.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-26063 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-26062Intelbras rx 1500 firmware improper access control vulnerabilityAn access control issue in Intelbras RX1500 v2.2.9 and RX3000 v1.0.11 allows unauthenticated attackers to access the router's settings file and obtai…EPSS 1.1%7.3CVE-2025-26065Intelbras rx 1500 firmware cross-site scripting vulnerabilityA cross-site scripting (XSS) vulnerability in Intelbras RX1500 v2.2.9 and RX3000 v1.0.11 allows attackers to execute arbitrary web scripts or HTML vi…EPSS 0.36%7.3CVE-2025-26064Intelbras rx 1500 firmware cross-site scripting vulnerabilityA cross-site scripting (XSS) vulnerability in Intelbras RX1500 v2.2.9 and RX3000 v1.0.11 allows attackers to execute arbitrary web scripts or HTML vi…EPSS 1.0%6.5CVE-2025-50405Intelbras rx 1500 firmware improper access control vulnerabilityIntelbras RX1500 Router v2.2.17 and before is vulnerable to Incorrect Access Control in the FirmwareUpload function and GetFirmwareValidation functio…EPSS 0.33%5.4CVE-2023-6103Intelbras rx 1500 firmware cross-site scripting vulnerabilityA vulnerability has been found in Intelbras RX 1500 1.1.9 and classified as problematic. Affected by this vulnerability is an unknown functionality o…EPSS 0.55%5.3CVE-2025-50404Intelbras rx 1500 firmware integer overflow vulnerabilityIntelbras RX1500 Router v2.2.17 and before is vulnerable to Integer Overflow. The websReadEvent function incorrectly uses the int type when processin…EPSS 8.2%9.8CVE-2026-8037Progress LoadMaster API OS Command Injection RCEProgress LoadMaster (and related ADC products) contain an OS command injection flaw in multiple API command endpoints where unsanitized input is pass…KEVEPSS 77%analysed8.7CVE-2026-42271LiteLLM MCP test endpoints allow authenticated OS command injectionLiteLLM versions 1.74.2 through before 1.83.7 expose two MCP preview endpoints (POST /mcp-rest/test/connection and POST /mcp-rest/test/tools/list) th…KEVEPSS 13%analysed

Source: NIST National Vulnerability Database (record CVE-2025-26063), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.