VideoFlow Digital Video Protection DVP 2.10 contains an authenticated remote code execution vulnerability that allows attackers to execute system commands with root privileges. Attackers can exploit the vulnerability through a cross-site request forgery (CSRF) mechanism to gain unauthorized system access.
Metrics
Affected Vendors & Products
References
History
Tue, 28 Jul 2026 03:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 28 Jul 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Avg
Avg protection |
|
| CPEs | cpe:2.3:a:avg:protection:1.40.0.15:*:*:*:*:*:*:* cpe:2.3:a:avg:protection:2.10.0.5:*:*:*:*:*:*:* cpe:2.3:a:avg:protection:2.10:*:*:*:*:*:*:* |
|
| Vendors & Products |
Avg
Avg protection |
Wed, 24 Dec 2025 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | VideoFlow Digital Video Protection DVP 2.10 contains an authenticated remote code execution vulnerability that allows attackers to execute system commands with root privileges. Attackers can exploit the vulnerability through a cross-site request forgery (CSRF) mechanism to gain unauthorized system access. | |
| Title | VideoFlow Digital Video Protection DVP 2.10 Authenticated Remote Code Execution | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-07-28T01:46:48.150Z
Reserved: 2025-12-24T14:27:12.478Z
Link: CVE-2019-25255
Updated: 2025-12-24T20:01:10.974Z
Status : Deferred
Published: 2025-12-24T20:15:54.160
Modified: 2026-06-17T02:31:53.697
Link: CVE-2019-25255
No data.
OpenCVE Enrichment
No data.