HTTP PUT Request Handler Vulnerability in Intelbras InControl Software
CVE-2025-6765

5.3MEDIUM

Key Information:

Vendor

Intelbras

Status
Vendor
CVE Published:
27 June 2025

What is CVE-2025-6765?

A vulnerability exists in Intelbras InControl version 2.21.60.9, specifically within the HTTP PUT request handler component. This security flaw allows an attacker to manipulate file processing on the server, potentially leading to insufficient permissions and privilege escalation. The vulnerability can be exploited remotely, posing a significant risk to the integrity of the application. Despite early disclosure attempts to the vendor, there has been no response, increasing the urgency for users to address this risk.

Affected Version(s)

InControl 2.21.60.9

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

lorenzomoulin (VulDB User)
.