CVE-2025-26064
7.3Intelbras · RX1500 and RX3000
A cross-site scripting (XSS) vulnerability in Intelbras RX1500 and RX3000 routers allows unauthenticated attackers to execute arbitrary web scripts via a crafted payload in a connected device name.
Executive summary
A critical cross-site scripting vulnerability in Intelbras routers allows unauthenticated attackers to inject malicious scripts, posing a significant risk of session hijacking and unauthorized administrative actions.
Vulnerability
This is a stored cross-site scripting (XSS) vulnerability triggered by injecting a malicious payload into the name field of a connected device. The vulnerability is exploitable by an unauthenticated attacker, as indicated by the CVSS vector PR:N.
Business impact
A successful exploit allows an attacker to execute arbitrary scripts in the context of a user session, potentially leading to the compromise of administrative credentials or unauthorized configuration changes. With a CVSS score of 7.3, this flaw is categorized as High severity, as it facilitates unauthorized interaction with the web interface. This could lead to a loss of network control and significant reputational damage for organizations relying on these devices.
Remediation
Immediate Action: Review the provided vendor changelogs at the Intelbras support portal to verify if a firmware update addressing this vulnerability has been released for your specific hardware revision.
Proactive Monitoring: Monitor network traffic for anomalous device naming conventions and perform regular audits of the connected devices list within the router web interface.
Compensating Controls: Implement a strict network access control policy to prevent untrusted devices from connecting to the network, and utilize a WAF or firewall rules to restrict access to the router management interface.
Exploitation status
Public Exploit Available: No (The provided enrichment does not confirm a weaponized exploit or public PoC repository).
Analyst recommendation
Given the High severity rating and the presence of a known proof-of-concept, administrators should prioritize the identification of affected hardware. If a vendor patch is available, it must be applied immediately to prevent potential unauthorized access. If no patch is currently available for your specific firmware, restrict management interface access to trusted internal IP addresses only.