CVE-2018-25159

CRITICAL

Epross AVCON6 - Command Injection

Title source: llm

Description

Epross AVCON6 systems management platform contains an object-graph navigation language (OGNL) injection vulnerability that allows unauthenticated attackers to execute arbitrary commands by injecting malicious OGNL expressions. Attackers can send crafted requests to the login.action endpoint with OGNL payloads in the redirect parameter to instantiate ProcessBuilder objects and execute system commands with root privileges.

Exploits (1)

exploitdb WORKING POC
by Nassim Asrir · pythonwebappsjava
https://www.exploit-db.com/exploits/47379

Scores

CVSS v3 9.8
EPSS 0.0012
EPSS Percentile 30.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-1334
Status published
Products (1)
Epross/AVCON6 systems management platform
Published Mar 11, 2026
Tracked Since Mar 12, 2026