Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-67070-Intelbras-CFTV-MFA-Bypass — A critical vulnerability in the Intelbras NVD 9032 R Ftd IP CFTV device allows an attacker to bypass the multi-factor authentication during password recovery. This results in the ability to change the admin password and gain full access to the administrative panel. | Kitploit
Tools/GitHubGitHub/teteco/cve-2025-67070-intelbras-cftv-mfa-bypass
Authentication & AuthorizationVulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingRed Teaming
GitHubteteco/cve-2025-67070-intelbras-cftv-mfa-bypass

CVE-2025-67070-Intelbras-CFTV-MFA-Bypass

A critical vulnerability in the Intelbras NVD 9032 R Ftd IP CFTV device allows an attacker to bypass the multi-factor authentication during password recovery. This results in the ability to change the admin password and gain full access to the administrative panel.

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
View Repository
7 months agoNot yet reviewed

Intelbras NVD 9032 R Ftd – Critical Password Reset Vulnerability

Discovered by: Theo Cia

CVE: CVE-2025-67070

Status: Reported to vendor

Date Discovered: November 2025

Impact: Full administrative access via MFA bypass

Firmware: V2.800.00IB00C.0.T

Build Date: 2022-08-17

Summary

A critical vulnerability in the Intelbras NVD 9032 R Ftd IP CFTV device allows an attacker to bypass the multi-factor authentication during password recovery. This results in the ability to change the admin password and gain full access to the administrative panel.

Vulnerability Details

Affected component: Password recovery endpoint

Vulnerability class: Improper Access Control (CWE-284)

Attack vector: Web-based response manipulation (interception/proxy)

Impact

This vulnerability allows unauthenticated attackers to:

Reset the admin password

Bypass multi-factor authentication

Gain full administrative access to the NVR panel

Mitigation

No official fix is available as of the publication date. Intelbras has been notified.

Contact

For more information or coordination, please contact: [email protected]

Download Tool