Junglewise Threat Intelligence

CVE-2026-12211: Intelbras iNVU 7016 FT path traversal in web interface

CVE-2026-12211 · Severity: low · CVSS 2.7 · Published 2026-06-15

Executive brief

A security vulnerability exists in the Intelbras iNVU 7016 FT, a professional-grade network video recorder (NVR) used for corporate surveillance. An attacker with low-level access to the device's web interface can exploit this flaw to read sensitive system files, including password hashes and encryption keys. This could lead to a full compromise of the device, unauthorized access to video feeds, or further attacks on the corporate network.

Technical details

A path traversal vulnerability (CWE-22) exists in the Intelbras iNVU 7016 FT NVR within the web interface's execution log download functionality. The endpoint '/RPC2_Loadfile/syslog/' fails to properly validate or sanitize user-supplied file paths, allowing an attacker to use directory traversal sequences (e.g., '../../') to access files outside the intended directory. Because the web server process runs with root privileges, an authenticated attacker with 'Storage', 'Maintenance', or 'System' permissions can read sensitive files such as /etc/shadow and SSH private keys. The product is based on the Dahua codebase, suggesting other OEM devices using similar firmware may also be affected. A fix has been released by the vendor.

Affected products

  • Intelbras iNVU 7016 FT 3.004.00IB000.0.T Build 2025-09-26

Timeline

  • 2025-09-26: other: Vulnerable build date
  • 2026-01-01: disclosed: Vulnerability discovered and reported to vendor
  • 2026-05-29: patched: Fixed firmware version released
  • 2026-06-15: advisory: CVE published

References