backend.intelbras.comrelated
https://backend.intelbras.com/sites/default/files/2025-08/Aviso%20de%20Seguran%C3%A7a%20-%20Incontrol%202.21.60%20e%202.21.61%20PT-IN%20.pdf CVE-2025-8515
LOW
Intelbras InControl JSON Endpoint operador information disclosure
Record summary
CVE-2025-8515 has a selected CVSS score of 2.3 (low).
Description
A weakness has been identified in Intelbras InControl 2.21.60.9. This vulnerability affects unknown code of the file /v1/operador/ of the component JSON Endpoint. Executing manipulation can lead to information disclosure. It is possible to launch the attack remotely. A high complexity level is associated with this attack. It is stated that the exploitability is difficult. The exploit has been made available to the public and could be exploited. Upgrading the affected component is advised.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 4, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
InControlBrowse Intelbras / InControl | CVE List | 2.21.60.9 | affected |
References
5nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-8515 VDB-318641 | CTI Indicators (IOB, IOC, TTP, IOA)signaturepermissions required
https://vuldb.com/?ctiid.318641 VDB-318641 | Intelbras InControl JSON Endpoint operador information disclosurevdb entryTechnical description
https://vuldb.com/?id.318641 Submit #579544 | Intelbras InControl 2.21.60.9 Information DisclosureThird-party advisory
https://vuldb.com/?submit.579544