Teradek VidiU Pro 3.0.3 contains a cross-site request forgery vulnerability that allows attackers to change administrative passwords without proper request validation. Attackers can craft malicious web pages that automatically submit password change requests to the device when a logged-in administrator visits the page.
Metrics
Affected Vendors & Products
References
History
Wed, 24 Dec 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 24 Dec 2025 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Teradek VidiU Pro 3.0.3 contains a cross-site request forgery vulnerability that allows attackers to change administrative passwords without proper request validation. Attackers can craft malicious web pages that automatically submit password change requests to the device when a logged-in administrator visits the page. | |
| Title | Teradek VidiU Pro 3.0.3 Cross-Site Request Forgery via Password Change | |
| Weaknesses | CWE-352 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2025-12-24T20:22:04.713Z
Reserved: 2025-12-24T14:27:12.478Z
Link: CVE-2019-25252
Updated: 2025-12-24T20:01:43.578Z
Status : Received
Published: 2025-12-24T20:15:53.700
Modified: 2025-12-24T21:16:03.240
Link: CVE-2019-25252
No data.
OpenCVE Enrichment
No data.