CVE-2019-25255
Severity CVSS v4.0:
HIGH
Type:
CWE-78
OS Command Injections
Publication date:
24/12/2025
Last modified:
24/12/2025
Description
VideoFlow Digital Video Protection DVP 2.10 contains an authenticated remote code execution vulnerability that allows attackers to execute system commands with root privileges. Attackers can exploit the vulnerability through a cross-site request forgery (CSRF) mechanism to gain unauthorized system access.
Impact
Base Score 4.0
8.70
Severity 4.0
HIGH
Base Score 3.x
4.30
Severity 3.x
MEDIUM



