CVE-2018-25310

VideoFlow Digital Video Protection DVP 2.10 contains an authenticated remote code execution vulnerability that allows authenticated attackers to execute arbitrary system commands by exploiting a cross-site request forgery flaw in the web management interface. Attackers with valid credentials can leverage the CSRF vulnerability to inject and execute system commands through the Tools > System > Shell interface, gaining root-level access to the device.
Configurations

No configuration.

History

30 Apr 2026, 13:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-29 20:16

Updated : 2026-06-17 01:55


NVD link : CVE-2018-25310

Mitre link : CVE-2018-25310

CVE.ORG link : CVE-2018-25310


JSON object : View

Products Affected

No product.

CWE
CWE-352

Cross-Site Request Forgery (CSRF)