Junglewise Threat Intelligence

CVE-2026-36438: Intelbras VIP-1230 Series information disclosure in password reset

CVE-2026-36438 · Severity: medium · CVSS 5.3 · Published 2026-05-18

Executive brief

Intelbras VIP-1230 series security cameras are affected by a vulnerability in their password reset feature. A remote attacker can exploit this flaw to obtain sensitive information about the administrator account without needing any prior credentials. This could lead to unauthorized access to the camera's management interface, potentially compromising video feeds or device settings.

Technical details

An information disclosure vulnerability exists in the Intelbras VIP-1230-D-G4 and VIP-1230-B-G4 firmware version V2.800.00IB00C.0.T. The flaw is located within the password reset functionality handled by the '/OutsideCmd' endpoint. A remote, unauthenticated attacker can send crafted requests to this component to leak sensitive information related to the administrator account. This issue is categorized as an improper restriction of sensitive information disclosure. While the CVSS score is 5.3 (Medium) due to the limited scope of data leakage, it serves as a critical reconnaissance step for further account takeover.

Affected products

  • Intelbras VIP-1230-D-G4 V2.800.00IB00C.0.T
  • Intelbras VIP-1230-B-G4 V2.800.00IB00C.0.T

Timeline

  • 2026-02: disclosed: Vulnerability discovered by Henrique Koji
  • 2026-05-18: advisory: CVE published to NVD dataset

References