CVE-2025-26065
7.3Intelbras · RX1500 and RX3000
A cross-site scripting (XSS) vulnerability exists in Intelbras RX1500 and RX3000 routers, allowing unauthenticated attackers to execute arbitrary scripts via crafted Wi-Fi network names.
Executive summary
An unauthenticated cross-site scripting vulnerability in Intelbras RX1500 and RX3000 routers poses a risk of unauthorized script execution and potential session hijacking.
Vulnerability
This vulnerability is a stored cross-site scripting (XSS) flaw where an attacker can inject malicious web scripts into the Wi-Fi network name field. The vulnerability is exploitable by unauthenticated attackers as identified by the CVSS vector AV:N/AC:L/PR:N.
Business impact
The vulnerability carries a CVSS score of 7.3, reflecting a high risk due to the potential for unauthorized execution of client-side scripts within the administrative interface. Successful exploitation could lead to session hijacking, unauthorized configuration changes, or the redirection of users to malicious sites, ultimately compromising the integrity of the network management environment.
Remediation
Immediate Action: Review the official Intelbras changelogs for the RX1500 and RX3000 series to identify and apply the latest firmware updates that address this issue.
Proactive Monitoring: Monitor device logs for unusual characters or script tags appearing in wireless network settings or interface logs.
Compensating Controls: Restrict management interface access to trusted administrative subnets and implement network segmentation to limit the exposure of the router management console to untrusted wireless clients.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Given the ease of access and the potential for full control over the administrative session, administrators should prioritize updating these devices to the latest available firmware. If a patch is not immediately available for your specific deployment, ensure that administrative access to the router is strictly isolated from public or untrusted wireless network segments.