Credential Storage Vulnerability in Intelbras UnniTI Product
CVE-2025-13221
Key Information:
Badges
What is CVE-2025-13221?
A vulnerability exists in Intelbras UnniTI version 24.07.11, specifically within the /xml/sistema/usuarios.xml file. An unchecked manipulation involving Usuario/Senha can lead to the storage of sensitive credentials in an unprotected manner. This weakness can be exploited remotely, allowing potential attackers to access credentials that should otherwise be secure. The exploit is publicly available, raising significant concerns for users and administrators who may be unaware of their system's vulnerabilities.
Affected Version(s)
UnniTI 24.07.11
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved
