CVE-2018-25150 Details
Description
Ecessa ShieldLink SL175EHQ 10.7.4 contains a cross-site request forgery vulnerability that allows attackers to create administrative user accounts without authentication. Attackers can craft a malicious web page with a hidden form to add a superuser account by tricking a logged-in administrator into loading the page.
A cross-site request forgery (CSRF) vulnerability has been identified in Ecessa ShieldLink SL175EHQ version 10.7.4. This vulnerability allows attackers to create administrative user accounts without authentication. By crafting a malicious web page with a hidden form, attackers can trick a logged-in administrator into loading the page, thereby adding a superuser account.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Dec 24, 2025CISA-ADP
Assessed Dec 24, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.ecessa.com | [email protected] | Vendor |
| https://www.exploit-db.com/exploits/44938 | [email protected] | Exploit |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-352 | Cross-Site Request Forgery (CSRF) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Ecessa ShieldLink SL175EHQ | 10.7.4 (semver) 10.6.9 (semver) 10.6.5.2 10.5.4 (semver) 10.2.24 (semver) 9.2.24 (semver) |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Dec 24, 2025 | New CVE Received | [email protected] |
Volerion