Cross-Site Request Forgery Vulnerability in Teradek VidiU Pro
CVE-2019-25252
Key Information:
Badges
What is CVE-2019-25252?
The Teradek VidiU Pro version 3.0.3 is susceptible to a cross-site request forgery (CSRF) vulnerability, which poses a significant security risk. This flaw enables attackers to manipulate administrative functions by sending crafted requests to the device. When an administrator inadvertently visits a malicious web page, it can automatically trigger password change requests, allowing for unauthorized access without the need for proper request validation.
Affected Version(s)
VidiU Pro 3.0.3
VidiU Pro 3.0.2
VidiU Pro 2.4.10
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
