Teradek manufactures specialized video streaming and encoding appliances, primarily the Vidiú and Slice product lines, which operate as edge devices in broadcast and live-event workflows. The vendor's disclosures cluster around web-interface vulnerabilities—cross-site scripting, cross-site request forgery, and server-side request forgery—reflecting the networked control surfaces and browser-based management interfaces typical of such appliances. Current severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Teradek over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-25251MEDIUM Teradek VidiU Pro 3.0.3 contains a server-side request forgery vulnerability in the management interface that allows attackers to manipulate GET parameters 'url' and 'xml_url'. Att | Dec 24, 2025 | 6.5 | 22 | NO | NO |
CVE-2021-37377MEDIUM Cross Site Scripting (XSS) vulnerability in Teradek Brik firmware version 7.2.x and earlier allows remote attackers to run arbitrary code via the Friendly Name field in System Info | Feb 3, 2023 | 5.4 | 20 | NO | NO |
CVE-2021-37379MEDIUM Cross Site Scripting (XSS) vulnerability in Teradek Sphere all firmware versions allows remote attackers to run arbitrary code via the Friendly Name field in System Information Set | Feb 3, 2023 | 5.4 | 19 | NO | NO |
CVE-2021-37376MEDIUM Cross Site Scripting (XSS) vulnerability in Teradek Bond, Bond 2 and Bond Pro firmware version 7.3.x and earlier allows remote attackers to run arbitrary code via the Friendly Name | Feb 3, 2023 | 5.4 | 19 | NO | NO |
CVE-2021-37375MEDIUM Cross Site Scripting (XSS) vulnerability in Teradek VidiU / VidiU Mini firmware version 3.0.8 and earlier allows remote attackers to run arbitrary code via the Friendly Name field | Feb 3, 2023 | 5.4 | 19 | NO | NO |
CVE-2021-37374MEDIUM Cross Site Scripting (XSS) vulnerability in Teradek Clip all firmware versions allows remote attackers to run arbitrary code via the Friendly Name field in System Information Setti | Feb 3, 2023 | 5.4 | 19 | NO | NO |
CVE-2021-37373MEDIUM Cross Site Scripting (XSS) vulnerability in Teradek Slice 1st generation firmware 7.3.x and earlier allows remote attackers to run arbitrary code via the Friendly Name field in Sys | Feb 3, 2023 | 5.4 | 19 | NO | NO |
CVE-2019-25252MEDIUM Teradek VidiU Pro 3.0.3 contains a cross-site request forgery vulnerability that allows attackers to change administrative passwords without proper request validation. Attackers ca | Dec 24, 2025 | 4.3 | 17 | NO | NO |
CVE-2018-25156MEDIUM Teradek Cube 7.3.6 contains a cross-site request forgery vulnerability that allows attackers to change administrative passwords without proper request validation. Attackers can cra | Dec 24, 2025 | 4.3 | 17 | NO | NO |
CVE-2018-25155MEDIUM Teradek Slice 7.3.15 contains a cross-site request forgery vulnerability that allows attackers to change administrative passwords without proper request validation. Attackers can c | Dec 24, 2025 | 4.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Teradek.
Media articles that mention a CVE ID that affects a product developed by Teradek — matched by CVE ID, not by vendor name.