CVE-2019-25255

Severity CVSS v4.0:
HIGH
Type:
CWE-78 OS Command Injections
Publication date:
24/12/2025
Last modified:
24/12/2025

Description

VideoFlow Digital Video Protection DVP 2.10 contains an authenticated remote code execution vulnerability that allows attackers to execute system commands with root privileges. Attackers can exploit the vulnerability through a cross-site request forgery (CSRF) mechanism to gain unauthorized system access.