← Πίσω στην αναζήτηση CVE

CVE-2018-25310

VideoFlow Digital Video Protection DVP

Περιγραφή

VideoFlow Digital Video Protection DVP 2.10 contains an authenticated remote code execution vulnerability that allows authenticated attackers to execute arbitrary system commands by exploiting a cross-site request forgery flaw in the web management interface. Attackers with valid credentials can leverage the CSRF vulnerability to inject and execute system commands through the Tools > System > Shell interface, gaining root-level access to the device.

CVSS 4.3EPSS 0.212%Κίνδυνος 0.44
Προβολή πηγής
Δημοσίευση
2026-04-29 20:16:26
Επηρεαζόμενες εκδόσεις
<2.11
Τύπος
Υλικολογισμικό
Διάνυσμα
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N