CVE-2025-67070
8.2Intelbras · CFTV IP NVD 9032 R Ftd
An unauthenticated multi-factor authentication bypass vulnerability exists in the Intelbras CFTV IP NVD 9032 R Ftd firmware, allowing attackers to reset the administrator password.
Executive summary
An unauthenticated bypass vulnerability in Intelbras NVD 9032 R Ftd devices allows remote attackers to compromise administrative credentials and gain full system access.
Vulnerability
This is an authentication bypass vulnerability affecting the password recovery process. It allows an unauthenticated attacker to circumvent multi-factor authentication, modify the administrative password, and achieve unauthorized access to the management console.
Business impact
Successful exploitation poses a severe risk to organizational security, as it grants an attacker complete control over surveillance infrastructure. With administrative access, an attacker could intercept video feeds, modify system configurations, or utilize the device as a pivot point for further network infiltration. The CVSS score of 8.2 reflects the high risk associated with unauthenticated remote access to critical security hardware.
Remediation
Immediate Action: Restrict network access to the device management interface by placing it behind a secure VPN or an isolated VLAN, as a vendor patch is currently unknown.
Proactive Monitoring: Monitor system logs for repeated or unauthorized password recovery attempts and anomalous administrative logins from unexpected IP addresses.
Compensating Controls: Implement strict firewall rules to prevent external, unauthorized access to the device management interface, effectively limiting the attack surface to trusted internal segments.
Exploitation status
Public Exploit Available: Yes, a public proof-of-concept repository exists on GitHub.
Analyst recommendation
Given the critical nature of this vulnerability, immediate mitigation is required to prevent unauthorized control of surveillance assets. Administrators should prioritize restricting network access to the affected devices until an official firmware patch is released by Intelbras to remediate the authentication flaw.