CVE-2026-2564
A security flaw has been discovered in Intelbras VIP 3260 Z IA 2.840.00IB005.0.T. Affected by this vulnerability is an unknown functionality of the file /OutsideCmd. The manipulation results in weak password recovery. It is possible to launch the attack remotely. Attacks of this nature are highly complex. The exploitation appears to be difficult. It is recommended to upgrade the affected component.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.2
- CVSS vector
- CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X
- EPSS probability
- 0.47%
- CWE
- CWE-640
- Published
- 2026-02-16
- Last modified
- 2026-03-12
Affected products
- Intelbras VIP 3260 Z IA
Weakness type
Related vulnerabilities
- CVE-2026-81905 — Concrete CMS below 9.5.3 does not enforce validation-hash type on redemption, allowing a hash issued for one purpose to be redeemed for another.
- CVE-2026-6285 — Improper Authentication in Ankaref's LIBRID/LIBREF
- CVE-2026-86260 — sfturing hosp_order Password Recovery CommonUserController.java modifyPassWord unverified password change
- CVE-2026-84699 — Team Password Manager before 14.184.308 Authentication Bypass in Password Reset
- CVE-2026-82487 — Beetel 450TC3 password recovery
- CVE-2026-19632 — TranslatePress – Multilingual <= 3.3.1 - Unauthenticated Account Takeover via Password Reset Link Disclosure
- CVE-2026-80196 — Kimai before 2.58.0 Authentication Bypass via Password Reset Link
- CVE-2026-77264 — Automation Web Platform <= 4.8.6 - Unauthenticated Authentication Bypass via 'otp_transient' Token Disclosure