CVE-2019-25472
HIGHIntelBras TIP200/TIP200 LITE - Info Disclosure
Title source: llmDescription
IntelBras Telefone IP TIP200 and 200 LITE contain an unauthenticated arbitrary file read vulnerability in the dumpConfigFile function accessible via the cgiServer.exx endpoint. Attackers can send GET requests to /cgi-bin/cgiServer.exx with the command parameter containing dumpConfigFile() to read sensitive files including /etc/shadow and configuration files without proper authorization.
Exploits (1)
References (3)
Scores
CVSS v3
7.5
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Classification
CWE
CWE-73
Status
draft
Timeline
Published
Mar 11, 2026
Tracked Since
Mar 12, 2026