← Vulnerability feed

Vulnerability record · CVE-2025-50404 · published 1 July 2025

CVE-2025-50404: Intelbras rx 1500 firmware integer overflow vulnerability

Intelbras · Rx 1500 Firmware

Intelbras RX1500 Router v2.2.17 and before is vulnerable to Integer Overflow. The websReadEvent function incorrectly uses the int type when processing the "command" field of the http header, causing the array to cross the boundary and overwrite other fields in the array.

5.3 CVSS 3.1 Medium EPSS 8.2% · top 5.3% CWE-190 · Integer overflow
5.3CVSS 3.1 base score
8.2%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

Intelbras RX1500 Router v2.2.17 and before is vulnerable to Integer Overflow. The websReadEvent function incorrectly uses the int type when processing the "command" field of the http header, causing the array to cross the boundary and overwrite other fields in the array.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-50404 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-26062Intelbras rx 1500 firmware improper access control vulnerabilityAn access control issue in Intelbras RX1500 v2.2.9 and RX3000 v1.0.11 allows unauthenticated attackers to access the router's settings file and obtai…EPSS 1.1%9.8CVE-2025-26063Intelbras rx 1500 firmware command injection vulnerabilityAn issue in Intelbras RX1500 v2.2.9 and RX3000 v1.0.11 allows unauthenticated attackers to execute arbitrary code via injecting a crafted payload int…EPSS 1.3%7.3CVE-2025-26065Intelbras rx 1500 firmware cross-site scripting vulnerabilityA cross-site scripting (XSS) vulnerability in Intelbras RX1500 v2.2.9 and RX3000 v1.0.11 allows attackers to execute arbitrary web scripts or HTML vi…EPSS 0.36%7.3CVE-2025-26064Intelbras rx 1500 firmware cross-site scripting vulnerabilityA cross-site scripting (XSS) vulnerability in Intelbras RX1500 v2.2.9 and RX3000 v1.0.11 allows attackers to execute arbitrary web scripts or HTML vi…EPSS 1.0%6.5CVE-2025-50405Intelbras rx 1500 firmware improper access control vulnerabilityIntelbras RX1500 Router v2.2.17 and before is vulnerable to Incorrect Access Control in the FirmwareUpload function and GetFirmwareValidation functio…EPSS 0.33%5.4CVE-2023-6103Intelbras rx 1500 firmware cross-site scripting vulnerabilityA vulnerability has been found in Intelbras RX 1500 1.1.9 and classified as problematic. Affected by this vulnerability is an unknown functionality o…EPSS 0.55%8.4CVE-2025-48595Android Framework integer overflow enables local code executionAn integer overflow in multiple locations of the Android Framework can be turned into code execution. It allows a local attacker to escalate privileg…KEVEPSS 1.7%analysed7.8CVE-2021-30952Apple WebKit integer overflow allows code execution via crafted web contentAn integer overflow in Apple's WebKit engine was fixed by improved input validation across tvOS 15.2, macOS Monterey 12.1, Safari 15.2, iOS/iPadOS 15…KEVEPSS 7.0%analysed

Source: NIST National Vulnerability Database (record CVE-2025-50404), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.