Remote Code Execution Vulnerability in VideoFlow Digital Video Protection DVP
CVE-2018-25310
Key Information:
- Vendor
Videoflow Ltd.
- Vendor
- CVE Published:
- 29 April 2026
Badges
What is CVE-2018-25310?
VideoFlow Digital Video Protection DVP version 2.10 is susceptible to an authenticated remote code execution vulnerability due to a cross-site request forgery (CSRF) flaw within the web management interface. This vulnerability permits attackers with legitimate credentials to exploit the CSRF weakness, enabling them to inject and execute arbitrary system commands via the Tools > System > Shell interface. Successful exploitation can grant adversaries root-level access to the device, posing significant security risks.
Affected Version(s)
VideoFlow Digital Video Protection 2.10
VideoFlow Digital Video Protection 1.40.0.15
VideoFlow Digital Video Protection 2.10.0.5
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
