CVE-2018-25159
CRITICALEpross AVCON6 - Command Injection
Title source: llmDescription
Epross AVCON6 systems management platform contains an object-graph navigation language (OGNL) injection vulnerability that allows unauthenticated attackers to execute arbitrary commands by injecting malicious OGNL expressions. Attackers can send crafted requests to the login.action endpoint with OGNL payloads in the redirect parameter to instantiate ProcessBuilder objects and execute system commands with root privileges.
Exploits (1)
Scores
CVSS v3
9.8
EPSS
0.0012
EPSS Percentile
30.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-1334
Status
published
Products (1)
Epross/AVCON6 systems management platform
Published
Mar 11, 2026
Tracked Since
Mar 12, 2026