Description
A vulnerability was identified in Intelbras TIP 125i 4.3.35/4.3.41. The affected element is an unknown function of the component Básico Page. Such manipulation leads to inclusion of sensitive information in source code. The attack can be launched remotely. A high complexity level is associated with this attack. The exploitability is described as difficult. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure.
Published: 2026-09-28
Score: 2.3 Low
EPSS: n/a
KEV: No
Impact: Sensitive information disclosure via remote access to the basic page
Action: Assess Impact
AI Analysis

Impact

A vulnerability in Intelbras TIP 125i firmware 4.3.35 and 4.3.41 allows an attacker to manipulate an unknown function in the Básico Page component, causing sensitive information to appear in the source code. The flaw falls under information disclosure weaknesses, and an attacker can obtain confidential details without authentication. The impact is limited to information exposure, not system compromise.

Affected Systems

Devices running Intelbras TIP 125i firmware versions 4.3.35 and 4.3.41 are affected. The vulnerability originates from an unknown function in the component responsible for rendering the Basic page.

Risk and Exploitability

The CVSS score is 2.3, indicating a low severity. Exploitation is considered difficult and requires high complexity to succeed, but the exploit is publicly available and the attack vector is remote through the web interface. EPSS is not available and the vulnerability is not listed in the CISA KEV catalog, so the current risk to organizations is low to moderate, contingent on exposure of the vulnerable page to external networks.

Generated by OpenCVE AI on September 29, 2026 at 00:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply a vendor‑supplied firmware update that removes the disclosed information from the source when it becomes available.
  • Restrict external access to the BASIC page by configuring firewalls or VLANs so that only trusted internal systems can reach it.
  • Change default or weak credentials on the device, enforce strong authentication for the BASIC page, and monitor access logs for unauthorized requests.

Generated by OpenCVE AI on September 29, 2026 at 00:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was identified in Intelbras TIP 125i 4.3.35/4.3.41. The affected element is an unknown function of the component Básico Page. Such manipulation leads to inclusion of sensitive information in source code. The attack can be launched remotely. A high complexity level is associated with this attack. The exploitability is described as difficult. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure.
Title Intelbras TIP 125i Básico sensitive information in source
First Time appeared Intelbras
Intelbras tip 125i
Weaknesses CWE-200
CWE-540
CPEs cpe:2.3:h:intelbras:tip_125i:*:*:*:*:*:*:*:*
Vendors & Products Intelbras
Intelbras tip 125i
References
Metrics cvssV2_0

{'score': 2.1, 'vector': 'AV:N/AC:H/Au:S/C:P/I:N/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 3.1, 'vector': 'CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 2.3, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Intelbras Tip 125i
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-28T23:30:10.163Z

Reserved: 2026-09-28T11:41:07.968Z

Link: CVE-2026-101265

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-29T00:17:02.833

Modified: 2026-09-29T00:17:02.833

Link: CVE-2026-101265

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-29T00:30:08Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-540

    Inclusion of Sensitive Information in Source Code