CVE-2019-25255: Videoflow Ltd Videoflow Digital Video Protection Dvp
Medium severity, CVSS 4.3. EPSS: 0.4% chance of exploitation in the next 30 days.
VideoFlow Digital Video Protection DVP 2.10 contains an authenticated remote code execution vulnerability that allows attackers to execute system commands with root privileges. Attackers can exploit the vulnerability through a cross-site request forgery (CSRF) mechanism to gain unauthorized system access.
Affected products
- Videoflow Ltd Videoflow Digital Video Protection Dvp: version 2.10 only; version 1.40.0.15 only; version 2.10.0.5 only
Published 2025-12-24. Last modified 2026-06-17.