CVE-2018-25159Disclosure

LOWCVSS 9.3 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Epross AVCON6 systems management platform contains an object-graph navigation language (OGNL) injection vulnerability that allows unauthenticated attackers to execute arbitrary commands by injecting malicious OGNL expressions. Attackers can send crafted requests to the login.action endpoint with OGNL payloads in the redirect parameter to instantiate ProcessBuilder objects and execute system commands with root privileges.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1334

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • Exploit: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-03-11); latest day: 1
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-03-11: 3Mentions · 2026-03-12: 1Patch / Workaround · 2026-03-11: 1Technical Details · 2026-03-11: 3Technical Details · 2026-03-12: 103-1103-12
Signal classification3 categories
Disclosure
250.0%
Exploit
125.0%
Patch
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-113
Disclosure1Exploit1Patch1
2026-03-121
Disclosure1
Full discourse4 posts
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2018-25159 — CVSS 9.8/10 ██████████ Epross AVCON6 systems management platform contains an object-graph navigation language (OGNL) injection vulnerability that allows unauthenti Severity: CRITICAL Is your org affected? Patch now. #cybersecurity #vulnerability https://t.co/3Q5ZeYzOM7

    Post summary

    The tweet highlights a critical OGNL injection flaw (CVE‑2018‑25159) in Epross AVCON6 and urges users to apply the available patch.

    1000048
    5 followersView on X
  • 0day Signal@0dayPublishing
    Exploit

    🚨 CVE-2018-25159: Epross AVCON6 OGNL Remote Code E... Unauthenticated OGNL injection through login.action redirect param = instant root shell via ProcessBuilder - classic St... https://zerodaysignal.com/vulnerability/CVE-2018-25159 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post documents an unauthenticated OGNL injection in Epross AVCON6 that can spawn a root shell via ProcessBuilder, and links to a Zero Day Signal page for further details.

    0001042
    143 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2018-25159 Epross AVCON6 systems management platform contains an object-graph navigation language (OGNL) injection vulnerability that allows unauthenticated attackers to execute… https://www.cve.org/CVERecord?id=CVE-2018-25159

    Post summary

    The text announces CVE‑2018‑25159 as an OGNL injection flaw in Epross AVCON6 that permits unauthenticated code execution, without providing any PoC, exploit, or active exploitation details.

    00000176
    56.7K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2018-25159: CRITICAL] Critical vulnerability in Epross AVCON6 systems management platform allows unauthenticated attackers to execute system commands with root privileges via OGNL injection.#cve,CVE-2018-25159,#cybersecurity https://cvefind.com/CVE-2018-25159

    Post summary

    The text announces a critical vulnerability (CVE-2018-25159) involving unrestrained OGNL injection in Epross AVCON6, enabling unauthenticated root command execution, with no PoC, exploit, patch or active exploitation details provided.

    0000037
    602 followersView on X

Explore more