CVE-2025-8515
Severity CVSS v4.0:
LOW
Type:
CWE-200
Information Leak / Disclosure
Publication date:
04/08/2025
Last modified:
29/10/2025
Description
A weakness has been identified in Intelbras InControl 2.21.60.9. This vulnerability affects unknown code of the file /v1/operador/ of the component JSON Endpoint. Executing manipulation can lead to information disclosure. It is possible to launch the attack remotely. A high complexity level is associated with this attack. It is stated that the exploitability is difficult. The exploit has been made available to the public and could be exploited. Upgrading the affected component is advised.
Impact
Base Score 4.0
2.30
Severity 4.0
LOW
Base Score 3.x
3.10
Severity 3.x
LOW
Base Score 2.0
2.10
Severity 2.0
LOW
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:intelbras:incontrol_web:2.21.60.9:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



