CVE-2026-2564 Details
Description
A security flaw has been discovered in Intelbras VIP 3260 Z IA 2.840.00IB005.0.T. Affected by this vulnerability is an unknown functionality of the file /OutsideCmd. The manipulation results in weak password recovery. It is possible to launch the attack remotely. Attacks of this nature are highly complex. The exploitation appears to be difficult. It is recommended to upgrade the affected component.
A critical vulnerability exists in the Intelbras VIP 3260 Z IA version 2.840.00IB005.0.T, allowing remote, unauthenticated attackers to exploit a weakness in the password recovery mechanism. The issue arises from inadequate server-side validation in the web interface, where the backend mistakenly relies on client-handled security code verifications. This flaw enables attackers to bypass the verification process and change the administrator password, leading to unauthorized access and control over the device, including the ability to view live camera feeds.
Users are advised to upgrade to the latest version of the Intelbras VIP 3260 Z IA firmware, as a patch has been released prior to the public disclosure of this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Feb 16, 2026CISA-ADP
Assessed Feb 17, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://vuldb.com/?ctiid.346171 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/?id.346171 | [email protected] | AdvisoryBundleRemedy |
| https://vuldb.com/?submit.741776 | [email protected] | Technical Description |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-640 | Weak Password Recovery Mechanism for Forgotten Password | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Intelbras VIP 3260 Z IA | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 16, 2026 | New CVE Received | [email protected] |
Volerion