CVE-2025-13221: Intelbras UnniTI usuarios.xml credentials storage

Published Nov 15, 2025
·
Updated

A weakness has been identified in Intelbras UnniTI 24.07.11. The affected element is an unknown function of the file /xml/sistema/usuarios.xml. Executing manipulation of the argument Usuario/Senha can lead to unprotected storage of credentials. The attack can be executed remotely. The exploit has been made available to the public and could be exploited.

Affected Software

1 affected component
Intelbras UnniTI

Event History

Nov 15, 2025
CVE Published
via MITRE·07:32 PM
Data Sourced
via MITRE·07:32 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeakness
Oct 25, 57844
Event
via NVD·10:04 AM

Frequently Asked Questions

1

What is the severity of CVE-2025-13221?

CVE-2025-13221 is considered a critical vulnerability due to its potential to expose unprotected credentials.

2

How do I fix CVE-2025-13221?

To fix CVE-2025-13221, ensure that sensitive credential storage and processing are securely handled, utilizing proper encryption measures.

3

What systems are affected by CVE-2025-13221?

CVE-2025-13221 affects Intelbras UnniTI version 24.07.11.

4

Can CVE-2025-13221 be exploited remotely?

Yes, CVE-2025-13221 can be exploited remotely by manipulating user credentials.

5

What kind of vulnerabilities does CVE-2025-13221 represent?

CVE-2025-13221 represents a weakness related to credential management in software applications.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203