Home

Description

A security flaw has been discovered in Intelbras VIP 3260 Z IA 2.840.00IB005.0.T. Affected by this vulnerability is an unknown functionality of the file /OutsideCmd. The manipulation results in weak password recovery. It is possible to launch the attack remotely. Attacks of this nature are highly complex. The exploitation appears to be difficult. It is recommended to upgrade the affected component.

PUBLISHED Reserved 2026-02-15 | Published 2026-02-16 | Updated 2026-02-23 | Assigner VulDB




CRITICAL: 9.2CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X
HIGH: 8.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:X/RL:O/RC:C
HIGH: 8.1CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:X/RL:O/RC:C
7.6AV:N/AC:H/Au:N/C:C/I:C/A:C/E:ND/RL:OF/RC:C

Problem types

Weak Password Recovery

Product status

2.840.00IB005.0.T
affected

Timeline

2026-02-15:Advisory disclosed
2026-02-15:VulDB entry created
2026-02-18:VulDB entry last update

Credits

ak7r4 (VulDB User) reporter

References

vuldb.com/?id.346171 (VDB-346171 | Intelbras VIP 3260 Z IA OutsideCmd password recovery) vdb-entry

vuldb.com/?ctiid.346171 (VDB-346171 | CTI Indicators (IOB, IOC, TTP, IOA)) signature permissions-required

vuldb.com/?submit.741776 (Submit #741776 | Intelbras VIP 3260 Z IA v2.840.00IB005.0.T Weak Password Recovery) third-party-advisory

cve.org (CVE-2026-2564)

nvd.nist.gov (CVE-2026-2564)

Download JSON