CVE-2026-12211: Intelbras iNVU 7016 FT Web syslog path traversal
A flaw has been found in Intelbras iNVU 7016 FT 3.004.00IB000.0.T Build 2025-09-26. This impacts an unknown function of the file /RPC2Loadfile/syslog/ of the component Web Interface. Executing a manipulation can lead to path traversal. The attack can be launched remotely. The exploit has been published and may be used. It is recommended to upgrade the affected component. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Intelbras iNVU 7016 FTto a version that resolves this vulnerability.Fixed in 3.004.00IB000.0.T Build 2025-09-26 - Compensating control
Since the attack can be launched remotely, restrict network access to the iNVU 7016 FT Web interface (including the Web syslog functionality) to only trusted sources (e.g., via firewall/ACL).
Event History
Frequently Asked Questions
What is the severity of CVE-2026-12211?
The severity of CVE-2026-12211 is classified as low.
How do I fix CVE-2026-12211?
To fix CVE-2026-12211, apply any available firmware updates from Intelbras for the iNVU 7016 FT device.
What impact does CVE-2026-12211 have on the Intelbras iNVU 7016 FT?
CVE-2026-12211 allows for path traversal vulnerabilities through the web interface, which may compromise file access.
Can CVE-2026-12211 be exploited remotely?
Yes, CVE-2026-12211 can be exploited remotely, allowing attackers to execute the path traversal attack.
What component of Intelbras iNVU 7016 FT is affected by CVE-2026-12211?
CVE-2026-12211 affects the web interface component of the Intelbras iNVU 7016 FT.