CVE-2018-25150
Unknown
Unknown - Not Provided
CSRF in Ecessa ShieldLink SL175EHQ Allows Admin Account Creation
Publication date: 2025-12-24
Last updated on: 2025-12-24
Assigner: VulnCheck
Description
Description
Ecessa ShieldLink SL175EHQ 10.7.4 contains a cross-site request forgery vulnerability that allows attackers to create administrative user accounts without authentication. Attackers can craft a malicious web page with a hidden form to add a superuser account by tricking a logged-in administrator into loading the page.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| ecessa | shieldlink | 10.7.4 |
| ecessa | shieldlink | 9.2.24 |
| ecessa | shieldlink | 10.5.4 |
| ecessa | shieldlink | 10.6.5.2 |
| ecessa | shieldlink | 10.2.24 |
| ecessa | shieldlink | 10.6.9 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-352 | The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor. |