CVE-2025-13221
⚪ Do wiadomości
Manipulacja argumentami w Intelbras UnniTI prowadzi do niechronionego przechowywania danych uwierzytelniających.
CVSS
5.3
EPSS
0.4%
Exploit
none
Vendor
Opis źródłowy (NVD)
A weakness has been identified in Intelbras UnniTI 24.07.11. The affected element is an unknown function of the file /xml/sistema/usuarios.xml. Executing manipulation of the argument Usuario/Senha can lead to unprotected storage of credentials. The attack can be executed remotely. The exploit has been made available to the public and could be exploited.
brak
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 5.3 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.4% |
| Opublikowano (NVD) | 2025-11-15 20:15:42 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-07 21:10:00 UTC |
Referencje
- https://vuldb.com/?ctiid.332537 ([email protected])
- https://vuldb.com/?id.332537 ([email protected])
- https://vuldb.com/?submit.685825 ([email protected])
- https://www.notion.so/eldruin/Intelbras-UnniTI-Plaintext-Admin-Credentials-Disclosure-29c27474cccb8008b2d7ea60affdf86e?source=copy_link ([email protected])