api-cronos.intelbras.com.brpatch
http://api-cronos.intelbras.com.br/download/INVU/INVU7016FT/prod/INVU7016FT-2026.05.29-712953bf2bb2af7e72d0577ad5ef6455.260527.BIN CVE-2026-12211
MEDIUM
Intelbras iNVU 7016 FT Web syslog path traversal
Record summary
CVE-2026-12211 has a selected CVSS score of 5.1 (medium).
Description
A flaw has been found in Intelbras iNVU 7016 FT 3.004.00IB000.0.T Build 2025-09-26. This impacts an unknown function of the file /RPC2_Loadfile/syslog/ of the component Web Interface. Executing a manipulation can lead to path traversal. The attack can be launched remotely. The exploit has been published and may be used. It is recommended to upgrade the affected component. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 15, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
iNVU 7016 FTBrowse Intelbras / iNVU 7016 FT | CVE List | 3.004.00IB000.0.T Build 2025-09-26 | affected |
References
7coaglio.comexploit
https://coaglio.com/writeups/lfi-intelbras-invu.html nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-12211 CVE-2026-12211 | CVE Analysis and ReportThird-party advisory
https://vuldb.com/cve/CVE-2026-12211 Submit #832544 | Intelbras iNVU 7016 FT 3.004.00IB000.0.T (Build 2025-09-26) Path TraversalThird-party advisory
https://vuldb.com/submit/832544 VDB-370853 | Intelbras iNVU 7016 FT Web syslog path traversalvdb entry
https://vuldb.com/vuln/370853 VDB-370853 | CTI Indicators (IOB, IOC, TTP, IOA)signaturepermissions required
https://vuldb.com/vuln/370853/cti