Sceawere
Vulnerability Detail
CVE-2026-101265UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Intelbras TIP 125i Information Disclosure
Vulnerability Metadata
- Severity
- Low
- Score / CVSS
- 3.1
- Creation Date
- 7h ago
- Vendor
- Intelbras
- Product
- TIP 125i
- Attack Type
- Inclusion of Sensitive Information in Source Code
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
- Attack Complexity
- HIGH
Narrative and Response
Description
A vulnerability was identified in Intelbras TIP 125i 4.3.35/4.3.41. The affected element is an unknown function of the component Básico Page. Such manipulation leads to inclusion of sensitive information in source code. The attack can be launched remotely. A high complexity level is associated with this attack. The exploitability is described as difficult. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "3.1",
"pubDate": "2026-09-29T00:17:02.833Z",
"pubdate": "2026-09-29T00:17:02.833Z",
"executiveSummary": "A critical security vulnerability has been identified in the Intelbras TIP 125i (versions 4.3.35 and 4.3.41), specifically involving the 'Básico Page' component. This vulnerability allows for the unauthorized inclusion of sensitive information directly into the application's source code output.\nCategorized as an information disclosure issue, this flaw enables remote attackers to access potentially sensitive data by exploiting the application's response handling. While the attack is characterized by high complexity and a difficult exploitation path, the public availability of an exploit increases the operational risk for environments using these devices.\nImpact includes the potential exposure of configuration details, credentials, or other system-level secrets that may facilitate further unauthorized access or persistent compromise of the telephony infrastructure. Organizations utilizing these affected versions should prioritize hardening measures and network segmentation to mitigate the risk of remote reconnaissance and data extraction.",
"technicalDetails": "The vulnerability resides within the 'Básico Page' component of the Intelbras TIP 125i firmware versions 4.3.35 and 4.3.41. The root cause is an improper handling of input or state within this specific web interface module, which results in the leakage of sensitive data—potentially including system variables, session tokens, or sensitive configuration strings—embedded within the rendered HTML source code.\nFrom a technical perspective, the vulnerability is classified as an Information Disclosure flaw. The exploitation process involves a remote attacker interacting with the 'Básico Page' function. Although the attack is designated as having high complexity, the mechanism typically involves crafting specific HTTP requests that trigger the component to disclose internal states or sensitive memory fragments within the HTTP response body.\nThe attack flow proceeds as follows: First, the attacker identifies the network-accessible 'Básico Page' endpoint on the target device. Second, due to the identified vulnerability, the attacker submits malformed or specific parameter sets to this component. Third, the application fails to sanitize or restrict the output, causing the server-side logic to inadvertently echo protected information into the generated client-side source code. An attacker viewing the page source—which may otherwise appear benign or partially broken—can identify the sensitive information embedded within the script or metadata sections.\nThe exposure of this sensitive information can lead to severe post-exploitation consequences. Depending on the data disclosed, an attacker may gain administrative insights, bypass secondary authentication mechanisms, or obtain enough technical details to craft subsequent, more severe exploits. Because the exploit code is publicly available, the barrier to entry for a motivated threat actor is significantly reduced, despite the 'difficult' classification. The vulnerability persists regardless of the user's privilege level if the endpoint is reachable, making it a critical concern for exposed management interfaces."
}