A cross-site scripting (XSS) vulnerability in Intelbras RX1500 v2.2.9 and RX3000 v1.0.11 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the name of a connnected device.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://manuais.intelbras.com.br/manual-linha-rx/ChangeLogRX1500.html | release notes |
https://manuais.intelbras.com.br/manual-linha-rx/ChangeLogRX3000.html | release notes |
https://seclists.org/fulldisclosure/2025/Jul/14 | mailing list third party advisory exploit |