CVE-2025-8515 LOW

CVE-2025-8515: Intelbras InControl JSON Endpoint operador information disclosure

Vendor Intelbras
Product InControl
Weakness CWE-200 · Info exposure
Published August 4, 2025
Last update October 29, 2025

CVSS base score

2.3/10
Attack vector Network
Attack complexity High
Privileges required Low
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P

What the vulnerability does

01Description

A weakness has been identified in Intelbras InControl 2.21.60.9. This vulnerability affects unknown code of the file /v1/operador/ of the component JSON Endpoint. Executing manipulation can lead to information disclosure. It is possible to launch the attack remotely. A high complexity level is associated with this attack. It is stated that the exploitability is difficult. The exploit has been made available to the public and could be exploited. Upgrading the affected component is advised.

Key dates

02Disclosure timeline

August 4, 2025 CVE published
October 29, 2025 Record updated