CVE-2026-36438
5.3 MEDIUMAn issue in Intelbras VIP-1230-D-G4 Version V2.800.00IB00C.0.T allows a remote attacker to obtain sensitive information via password rese...
Published: 2026-05-18 · Last updated: 2026-05-19
Severity and scoring
- CVSS
- 5.3 MEDIUM
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- CWE
- CWE-640
Description
An issue in Intelbras VIP-1230-D-G4 Version V2.800.00IB00C.0.T allows a remote attacker to obtain sensitive information via password reset functionality under /OutsideCmd
Source: NVD
References
- [NVD]https://nvd.nist.gov/vuln/detail/CVE-2026-36438
- [Other]https://backend.intelbras.com/sites/default/files/2023-03/Datasheet%20UNIFICADO%20-%20VIP%201230%20B.D.G4-v2.pdf
- [Other]https://github.com/kensh1k/CVE-2026-36438/tree/main
- [Other]https://www.intelbras.com/pt-br/camera-dome-wi-fi-vip-1230-d-w-g4
Related CVEs
Same CWE
- CVE-2026-45013 — ApostropheCMS is an open-source Node.js content management system (8.1 HIGH)
- CVE-2026-12066 — A security flaw has been discovered in PbootCMS up to 3.2.12 (7.3 HIGH)
- CVE-2026-50635 — LimeSurvey constructs account password-reset links from the client-supplied HTTP Host header without validating it (8.8 HIGH)
- CVE-2026-10169 — A vulnerability was detected in OUSL-GROUP-BrinaryBrains School Student Management System up to 1e70e5ad1125b86dca4ee086eb6bb121f17708b6 (3.7 LOW)
- CVE-2026-7459 — The Simple History – Track, Log, and Audit WordPress Changes plugin for WordPress is vulnerable to authenticated (Subscriber+) account ta... (7.5 HIGH)