CVE-2026-3101
Last modified
CVE-2026-3101 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. A vulnerability was found in Intelbras TIP 635G 1.12.3.5. This vulnerability affects unknown code of the component Ping Handler. EPSS estimates a 3.49% chance of exploitation in the next 30 days.
Description
A vulnerability was found in Intelbras TIP 635G 1.12.3.5. This vulnerability affects unknown code of the component Ping Handler. The manipulation results in os command injection. The attack can be executed remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Intelbras | Tip 635g Firmware | 1.12.3.5 |
References
- https://vuldb.com/?ctiid.347527Permissions Required
- https://vuldb.com/?id.347527Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.757986Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-3101?
How severe is CVE-2026-3101?
How do I fix CVE-2026-3101?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-30995Slah CMS v1.5.0 and below was discovered to contain a SQL in…8.6
- CVE-2026-30996An issue in the file handling logic of the component downloa…7.5
- CVE-2026-30997An out-of-bounds read in the read_global_param() function (l…7.5
- CVE-2026-30998An improper resource deallocation and closure vulnerability …7.5
- CVE-2026-30999A heap buffer overflow in the av_bprint_finalize() function …7.5
- CVE-2026-3100The FTP Backup on the ADM will not properly strictly enforce…6.5
- CVE-2026-31013Dovestones Softwares ADPhonebook <4.0.1.1 has a reflected cr…6.1
- CVE-2026-31014Dovestones Softwares AD Self Update <4.0.0.5 is vulnerable t…6.3
- CVE-2026-31016Cross Site Request Forgery vulnerability in Squidex.io Squid…6.5
- CVE-2026-31017A Server-Side Request Forgery (SSRF) vulnerability exists in…9.1
- CVE-2026-31018In Dolibarr ERP & CRM <= 22.0.4, PHP code detection and edit…8.8
- CVE-2026-31019In the Website module of Dolibarr ERP & CRM 22.0.4 and below…8.8
Are you affected by CVE-2026-3101?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
