Server-Side Request Forgery Vulnerability in Teradek VidiU Pro
CVE-2019-25251
Key Information:
- Vendor
Teradek, Llc
- Status
- Vendor
- CVE Published:
- 24 December 2025
Badges
What is CVE-2019-25251?
The Teradek VidiU Pro version 3.0.3 is vulnerable to a server-side request forgery (SSRF) due to flaws in its management interface. This vulnerability allows attackers to manipulate the GET parameters 'url' and 'xml_url', enabling them to bypass firewall protections, conduct network enumeration, and potentially execute external HTTP requests to arbitrary destinations. Such exploitation could lead to serious consequences for the integrity and confidentiality of networked resources.
Affected Version(s)
VidiU Pro 3.0.3r32136
VidiU Pro 3.0.2r31225
VidiU Pro 2.4.10
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
