CVE-2025-26064: XSS
Published Jul 31, 2025
·Updated
A cross-site scripting (XSS) vulnerability in Intelbras RX1500 v2.2.9 and RX3000 v1.0.11 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the name of a connnected device.
Affected Software
6 affected components
Intelbras RX1500
Intelbras RX3000
All of the following
Intelbras Rx 1500 Firmware=2.2.9
Intelbras RX 1500
All of the following
Intelbras Rx 3000 Firmware=1.0.11
Intelbras Rx 3000
Event History
Jul 31, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-26064?
CVE-2025-26064 is classified as a high severity cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2025-26064?
To fix CVE-2025-26064, upgrade to Intelbras RX1500 version 2.2.10 or RX3000 version 1.0.12 or later.
3
What products are affected by CVE-2025-26064?
CVE-2025-26064 affects Intelbras RX1500 version 2.2.9 and RX3000 version 1.0.11.
4
What type of vulnerability is CVE-2025-26064?
CVE-2025-26064 is a cross-site scripting (XSS) vulnerability that allows the execution of arbitrary web scripts.
5
What can attackers do with CVE-2025-26064?
With CVE-2025-26064, attackers can inject crafted payloads into device names and execute malicious scripts.