Teradek VidiU
cpe:2.3:h:teradek:vidiu:*:*:*:*:*:*:*
- 3.0.3 (build 32136)
- 3.0.2 (build 31225)
- 2.4.10
A cross-site request forgery (CSRF) vulnerability has been identified in the Teradek VidiU Pro version 3.0.3, as well as in versions 3.0.2 and 2.4.10. This vulnerability allows attackers to change administrative passwords without proper request validation. By crafting malicious web pages that automatically submit password change requests, an attacker can exploit this issue when a logged-in administrator visits the page.
Exploitation of this vulnerability allows for unauthorized password changes, potentially leading to unauthorized access or actions on behalf of the administrator.
To reproduce this vulnerability, a logged-in administrator must be tricked into visiting a malicious web page that automatically submits a password change request to the Teradek VidiU Pro device. The request must include the new password, the password confirmation, and the username of the administrator.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.