PT-2025-53338 · Teradek · Teradek Vidiu Pro

Published

2025-12-24

·

Updated

2025-12-24

·

CVE-2019-25252

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Teradek VidiU Pro version 3.0.3
Description The Teradek VidiU Pro software contains a cross-site request forgery issue. This allows attackers to alter administrative passwords due to insufficient validation of requests. An attacker can create malicious web pages that automatically submit requests to change passwords when an administrator who is logged in visits the page.
Recommendations Apply updates to address the lack of proper request validation in password change operations.

Exploit

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2019-25252

Affected Products

Teradek Vidiu Pro