nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-6765 CVE-2025-6765
MEDIUM
Intelbras InControl HTTP PUT Request operador permission
Record summary
CVE-2025-6765 has a selected CVSS score of 5.3 (medium).
Description
A vulnerability, which was classified as critical, has been found in Intelbras InControl 2.21.60.9. This issue affects some unknown processing of the file /v1/operador/ of the component HTTP PUT Request Handler. The manipulation leads to permission issues. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 27, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
InControlBrowse Intelbras / InControl | CVE List | 2.21.60.9 | affected |
References
5VDB-314075 | CTI Indicators (IOB, IOC, TTP, IOA)signaturepermissions required
https://vuldb.com/?ctiid.314075 VDB-314075 | Intelbras InControl HTTP PUT Request operador permissionvdb entry
https://vuldb.com/?id.314075 Submit #599873 | Intelbras InControl 2.21.60.9 Improper Handling of Insufficient Permissions or PrivilegesThird-party advisory
https://vuldb.com/?submit.599873 Submit #599880 | Intelbras InControl 2.21.60.9 IDOR (Duplicate)Third-party advisory
https://vuldb.com/?submit.599880