Intelbras InControl Insecure Storage of Credentials Vulnerability

Vulnerability

A vulnerability exists in Intelbras InControl versions through 2.21.59, specifically within an unknown function on the Dispositivos Edição Page. The issue arises from the improper storage of communication password credentials, which can be accessed remotely. This vulnerability has been publicly disclosed and is reportedly being addressed in a future release.

Impact

Exploitation of this vulnerability allows for the unauthorized disclosure of stored password credentials, which could lead to unauthorized access or manipulation of related components.

Reproduction

To reproduce this vulnerability, an administrator must access the Dispositivos Edição Page and register external devices or addresses, including a communication password. Once the password is saved, it can be viewed in an insecure format (type='password') on the configuration screen. An attacker with administrative access can change the input type to 'text', exposing the password in plain view.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.3
impact
2.5
exploitability
4.7
remediation
0.0
relevance
0.0
threat
1.6
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.