CVE-2025-8515 is an information disclosure vulnerability found in Intelbras InControl 2.21.60.9, specifically within an unknown code segment of the /v1/operador/ JSON Endpoint. This vulnerability, while remotely exploitable, has a high attack complexity and a low CVSS score of 3.7. Although public exploit code exists, its difficult exploitability and lack of active exploitation, community discussion, or media coverage suggest a limited immediate threat. Organizations using affected Intelbras InControl versions are advised to upgrade.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.21.60.9CPE matchmatch criteria | cpe:2.3:a:intelbras:incontrol_web:2.21.60.9:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.