VideoFlow Digital Video Protection DVP Authenticated Remote Code Execution Vulnerability

Vulnerability

A remote code execution vulnerability has been identified in VideoFlow Digital Video Protection (DVP) version 2.10. This vulnerability allows authenticated attackers to execute arbitrary system commands by exploiting a cross-site request forgery (CSRF) flaw in the web management interface. Attackers with valid credentials can inject and execute commands through the Tools > System > Shell interface, gaining root access to the device.

Impact

Exploitation of this vulnerability allows authenticated users to execute arbitrary commands with root privileges on the affected device.

Reproduction

To reproduce this vulnerability, an authenticated user must log into the VideoFlow DVP web management interface. Once logged in, the user can navigate to the Tools > System > Shell section. Here, the CSRF vulnerability can be exploited to inject commands that will be executed with root privileges.

Added: Apr 29, 2026, 8:28 PM
Updated: Apr 29, 2026, 8:28 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
6.6
remediation
0.0
relevance
7.0
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.