Security Advisory

CVE-2018-25159

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-03-11 18:23:07
Last updated 2026-04-07 14:03:50
Assigner VulnCheck
CVSS score 9.3
State PUBLISHED

Description

Epross AVCON6 systems management platform contains an object-graph navigation language (OGNL) injection vulnerability that allows unauthenticated attackers to execute arbitrary commands by injecting malicious OGNL expressions. Attackers can send crafted requests to the login.action endpoint with OGNL payloads in the redirect parameter to instantiate ProcessBuilder objects and execute system commands with root privileges.