S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated May 31, 2025

CVE-2020-12262 Scanner

CVE-2020-12262 Scanner - Cross-Site Scripting (XSS) vulnerability in Intelbras TIP200/TIP200LITE/TIP300

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
3.1k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2020-12262
5.4
CVSS

Intelbras TIP200 60.61.75.15, TIP200LITE 60.61.75.15, and TIP300 65.61.75.15 devices allow /cgi-bin/cgiServer.exx?page= XSS.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

Intelbras TIP200/TIP200LITE/TIP300 are VoIP devices used for communication solutions. Widely deployed in corporate environments, these models are known for their ease of installation and integration with existing network structures. They are designed to provide high-quality audio communication, enhancing office productivity. Intelbras is a popular electronics company in Latin America, specializing in innovative products for security, communication, and networking. The TIP range of VoIP devices is an important part of their communication product line. Such devices are ideal for small to medium enterprises needing reliable office communication tools.

The Cross-Site Scripting (XSS) vulnerability detected in the Intelbras TIP200/TIP200LITE/TIP300 is a security flaw that allows attackers to inject malicious scripts into trusted websites. This vulnerability typically targets web applications with user interfaces, aiming to execute malicious scripts in the context of the user. XSS vulnerabilities can be exploited by attackers to steal cookies, session tokens, or other sensitive information retained by the browser. Such vulnerabilities arise when applications include unchecked user inputs into the content sent to the client browsers. If not managed, this can lead to various types of security breaches.

Technical details about this vulnerability involve the page parameter in the /cgi-bin/cgiServer.exx directory. This specific parameter fails to check and sanitize user inputs properly, allowing arbitrary JavaScript to execute. The attacker can craft a URL that includes a script alert to demonstrate the vulnerability. This vulnerability is triggered upon an unauthorized user accessing the vulnerable endpoint with malicious scripts. Successful exploitation requires user interaction, where the victim must click on a crafted URL sent by the attacker. The vulnerability impacts devices with specific firmware versions as stated.

When exploited, the Cross-Site Scripting (XSS) vulnerability can result in significant consequences. Attackers may execute arbitrary scripts in the context of the victim's browser, leading to session hijacking or stealing sensitive data. The risk escalates as attackers can impersonate users, alter the UI, or redirect users to malicious websites. Victims might experience unauthorized information disclosure, compromising privacy and security. In severe cases, exploitation can be part of a larger attack chain, facilitating further infiltration into network systems. Such breaches can disrupt trust in a company's communication infrastructure.

REFERENCES

Solution Advice
  • Update the device firmware to the latest version provided by Intelbras.
  • Implement input validation and sanitization on user inputs, especially those reflected to client browsers.
  • Use Content Security Policy (CSP) headers to prevent unauthorized script execution.
  • Regularly audit and test security of VOIP systems to identify and mitigate vulnerabilities promptly.
  • Train staff to recognize phishing and social engineering attacks to decrease risk exposure.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2020-12262 Scanner - Cross-Site Scripting (XSS) vulnerability in Intelbras TIP200/TIP200LITE/TIP300 | S4E