CNNVD-202512-4256 Information

CNNVD ID

CNNVD-202512-4256

CVE-2019-25251

  • CNNVD Published: 2025-12-24

Description (Chinese)

Teradek VidiU Pro是美国Teradek公司的一个硬件直播编码器。 Teradek VidiU Pro 3.0.3版本存在安全漏洞,该漏洞源于管理接口对url和xml_url参数处理不当,可能导致服务端请求伪造攻击。

Description (English)

Terradek VidiU Pro is a hardware live encoder of the United States company Terradek. There is a security loophole in Terradek VidiU Pro 3.03, which stems from the mishandling of the url and xml url parameters by the management interface, which may lead to the request of the service for a false attack.

Hazard Level

High

Vulnerability Type

其他

Affected Vendor

Teradek

Published

2025-12-24

Last Modified

2026-02-24

References

https://www.exploit-db.com/exploits/44672 https://www.teradek.com https://www.zeroscience.mk/en/vulnerabilities/ZSL-2018-5461.php

Share on: