CVE-2018-25159 is a critical OGNL injection vulnerability affecting the Epross AVCON6 systems management platform. This flaw allows unauthenticated attackers to execute arbitrary commands with root privileges by injecting malicious OGNL expressions into the 'redirect' parameter of the login.action endpoint. Rated 9.8 CVSS Critical, it poses a severe risk due to its network-based attack vector, low complexity, and complete compromise of system confidentiality, integrity, and availability. Despite this high severity, there is currently no evidence of active exploitation, public exploit code, or significant community attention for this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Epross | AVCON6 Systems Management Platform | All Versions ImpactedCNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.