CVE-2018-25151: Ecessa Corporation Wanworx Wvr-30

Medium severity, CVSS 4.3. EPSS: 0.1% chance of exploitation in the next 30 days.

Ecessa WANWorx WVR-30 versions before 10.7.4 contain a cross-site request forgery vulnerability that allows attackers to perform administrative actions without request validation. Attackers can craft a malicious web page with a hidden form to create a new superuser account by tricking an authenticated administrator into loading the page.

Affected products

  • Ecessa Corporation Wanworx Wvr-30: before 10.7.4 (fixed in 10.7.4); version 10.7.4 only; version 10.6.9 only; version 10.6.5.2 only; version 10.5.4 only; version 10.2.24 only; …

Published 2025-12-24. Last modified 2026-06-17.