Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 12 Mar 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Intelbras
Intelbras telefone Ip Tip 200 Intelbras telefone Ip Tip 200 Lite |
|
| Vendors & Products |
Intelbras
Intelbras telefone Ip Tip 200 Intelbras telefone Ip Tip 200 Lite |
Wed, 11 Mar 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 11 Mar 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 11 Mar 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 11 Mar 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IntelBras Telefone IP TIP200 and 200 LITE contain an unauthenticated arbitrary file read vulnerability in the dumpConfigFile function accessible via the cgiServer.exx endpoint. Attackers can send GET requests to /cgi-bin/cgiServer.exx with the command parameter containing dumpConfigFile() to read sensitive files including /etc/shadow and configuration files without proper authorization. | |
| Title | IntelBras Telefone IP TIP200/200 LITE Arbitrary File Read via dumpConfigFile | |
| Weaknesses | CWE-73 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-04-07T14:04:29.982Z
Reserved: 2026-02-22T14:43:03.387Z
Link: CVE-2019-25472
Updated: 2026-03-11T19:22:52.576Z
Status : Awaiting Analysis
Published: 2026-03-11T19:16:01.007
Modified: 2026-03-12T21:08:22.643
Link: CVE-2019-25472
No data.
OpenCVE Enrichment
Updated: 2026-03-20T15:29:47Z