Executive brief
A security vulnerability exists in the Intelbras iNVU 7016 FT, a professional-grade network video recorder (NVR) used for corporate surveillance. An attacker with low-level access to the device's web interface can exploit this flaw to read sensitive system files, including password hashes and encryption keys. This could lead to a full compromise of the device, unauthorized access to video feeds, or further attacks on the corporate network.
Technical details
A path traversal vulnerability (CWE-22) exists in the Intelbras iNVU 7016 FT NVR within the web interface's execution log download functionality. The endpoint '/RPC2_Loadfile/syslog/' fails to properly validate or sanitize user-supplied file paths, allowing an attacker to use directory traversal sequences (e.g., '../../') to access files outside the intended directory. Because the web server process runs with root privileges, an authenticated attacker with 'Storage', 'Maintenance', or 'System' permissions can read sensitive files such as /etc/shadow and SSH private keys. The product is based on the Dahua codebase, suggesting other OEM devices using similar firmware may also be affected. A fix has been released by the vendor.
Affected products
- Intelbras iNVU 7016 FT 3.004.00IB000.0.T Build 2025-09-26
Timeline
- 2025-09-26: other: Vulnerable build date
- 2026-01-01: disclosed: Vulnerability discovered and reported to vendor
- 2026-05-29: patched: Fixed firmware version released
- 2026-06-15: advisory: CVE published
References
- http://api-cronos.intelbras.com.br/download/INVU/INVU7016FT/prod/INVU7016FT-2026.05.29-712953bf2bb2af7e72d0577ad5ef6455.260527.BIN
- https://coaglio.com/writeups/lfi-intelbras-invu.html
- https://vuldb.com/cve/CVE-2026-12211
- https://vuldb.com/submit/832544
- https://vuldb.com/vuln/370853
- https://vuldb.com/vuln/370853/cti