Unrated severityNVD Advisory· Published Dec 24, 2025· Updated Jan 26, 2026
Teradek VidiU Pro 3.0.3 Server-Side Request Forgery via RTMP Settings
CVE-2019-25251
Description
Teradek VidiU Pro 3.0.3 contains a server-side request forgery vulnerability in the management interface that allows attackers to manipulate GET parameters 'url' and 'xml_url'. Attackers can exploit this flaw to bypass firewalls, initiate network enumeration, and potentially trigger external HTTP requests to arbitrary destinations.
Affected products
2= 3.0.3+ 1 more
- (no CPE)range: = 3.0.3
- (no CPE)range: 3.0.3r32136
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- www.exploit-db.com/exploits/44672mitreexploit
- www.zeroscience.mk/en/vulnerabilities/ZSL-2018-5461.phpmitrethird-party-advisory
- www.teradek.commitreproduct
News mentions
0No linked articles in our index yet.