CRITICAL🇵🇱 Wersja polska

CVE-2018-25159

CVSS 9.3v4.0pub. 2026-03-11upd. 2026-04-15

Epross AVCON6 systems management platform contains an object-graph navigation language (OGNL) injection vulnerability that allows unauthenticated attackers to execute arbitrary commands by injecting malicious OGNL expressions. Attackers can send crafted requests to the login.action endpoint with OGNL payloads in the redirect parameter to instantiate ProcessBuilder objects and execute system commands with root privileges.

🤖 AI Analysis
How it works

The attacker sends a crafted HTTP request to the login.action endpoint, placing a malicious OGNL expression in the redirect parameter. The platform processes the passed parameter without proper validation, allowing injection and execution of arbitrary code on the server side. Through the OGNL expression, the attacker can create instances of ProcessBuilder objects and use them to execute arbitrary system commands with root privileges.

Impact

An unauthenticated attacker can gain full control over the system by executing arbitrary commands with root privileges, which may lead to complete server takeover, data theft, and further lateral movement within the network.

Mitigation & patch

Patches available from the vendor should be applied according to the references. Additionally, until the fix is deployed, it is recommended to restrict network access to the login.action endpoint using firewall or ACL rules and monitor requests containing suspicious values of the redirect parameter.

Who is affected

Epross AVCON6 management platform — specific versions indicated in the vendor references and VulnCheck advisories

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References