CVE-2025-67070

HIGH

Intelbras CFTV IP NVD 9032 R Ftd V2.800.00IB00C.0.T - Auth Bypass

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2025-67070. PoCs published by teteco.

AI-analyzed exploit summary The repository describes an MFA bypass vulnerability (CVE-2025-67070) in Intelbras NVD 9032 R Ftd devices, allowing unauthenticated attackers to reset the admin password via web-based response manipulation. No exploit code is provided, only a detailed writeup.

Description

A vulnerability exists in Intelbras CFTV IP NVD 9032 R Ftd V2.800.00IB00C.0.T, which allows an unauthenticated attacker to bypass the multi-factor authentication (MFA) mechanism during the password recovery process. This results in the ability to change the admin password and gain full access to the administrative panel.

Exploits (1)

nomisec WRITEUP
by teteco · poc
https://github.com/teteco/CVE-2025-67070-Intelbras-CFTV-MFA-Bypass

The repository describes an MFA bypass vulnerability (CVE-2025-67070) in Intelbras NVD 9032 R Ftd devices, allowing unauthenticated attackers to reset the admin password via web-based response manipulation. No exploit code is provided, only a detailed writeup.

Classification
Writeup 90%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Theoretical
Target: Intelbras NVD 9032 R Ftd (Firmware V2.800.00IB00C.0.T)
No auth needed
Prerequisites: Network access to the device · Ability to intercept/proxy web traffic
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1

Scores

CVSS v3 8.2
EPSS 0.0033
EPSS Percentile 24.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-288
Status published
Published Jan 09, 2026
Tracked Since Feb 18, 2026