CVE-2018-25151: Ecessa Corporation Wanworx Wvr-30
Medium severity, CVSS 4.3. EPSS: 0.1% chance of exploitation in the next 30 days.
Ecessa WANWorx WVR-30 versions before 10.7.4 contain a cross-site request forgery vulnerability that allows attackers to perform administrative actions without request validation. Attackers can craft a malicious web page with a hidden form to create a new superuser account by tricking an authenticated administrator into loading the page.
Affected products
- Ecessa Corporation Wanworx Wvr-30: before 10.7.4 (fixed in 10.7.4); version 10.7.4 only; version 10.6.9 only; version 10.6.5.2 only; version 10.5.4 only; version 10.2.24 only; …
Published 2025-12-24. Last modified 2026-06-17.