CVE-2019-25472 is a high-severity unauthenticated arbitrary file read vulnerability affecting IntelBras Telefone IP TIP200 and 200 LITE devices. Attackers can exploit this flaw by sending simple GET requests to the cgiServer.exx endpoint, leveraging the dumpConfigFile function to access sensitive system files like /etc/shadow and configuration data without requiring any authentication. With a CVSS score of 7.5 (High), this network-exploitable vulnerability has a low attack complexity and no user interaction, posing a significant risk of confidentiality compromise. Despite its severity, there is currently no evidence of active exploitation, public exploit code (e.g., Metasploit, ExploitDB), or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Intelbras | Telefone IP TIP 200 LITE | All Versions ImpactedCNA affecteddefault unaffected | |
| Intelbras | Telefone IP TIP 200 | All Versions ImpactedCNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.