CVE-2018-25272Exploit

LOWCVSS 9.3 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

ELBA5 5.8.0 contains a remote code execution vulnerability that allows attackers to obtain database credentials and execute arbitrary commands with SYSTEM level permissions. Attackers can connect to the database using default connector credentials, decrypt the DBA password, and execute commands via the xp_cmdshell stored procedure or add backdoor users to the BEDIENER table.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-326

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC and exploit tooling are both present
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 2 signals
  • Technical details provided in 2 signals
  • Peaked 1d ago at 1 mentions (2026-04-22); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-22: 1Mentions · 2026-04-23: 1PoC Mentioned / Linked · 2026-04-22: 1PoC Mentioned / Linked · 2026-04-23: 1Exploit Tool / Code · 2026-04-22: 1Technical Details · 2026-04-22: 1Technical Details · 2026-04-23: 104-2204-23
Signal classification2 categories
Exploit
150.0%
PoC
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-04-221
Exploit1
2026-04-231
PoC1
Full discourse2 posts
  • 0day Signal@0dayPublishing
    Exploit

    🚨 CVE-2018-25272: ELBA5 5.8.0 R... Default creds + cleartext DBA passwords + xp_cmdshell = instant SYSTEM shells on every ELBA5 deployment. #RCE #DefaultCreds #SQLInjection. https://zerodaysignal.com/vulnerability/CVE-2018-25272 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet advertises how to sidestep ELBA5 5.8.0 security by leveraging default logins and xp_cmdshell for immediate SYSTEM access, linking to a vulnerability page but not providing a patch or confirming active attacks.

    0001053
    218 followersView on X
  • Cyber Threat Observatory | Alan Turing Institute@TuringCyberObs
    PoC

    CVE-2018-25272 (ELBA5 v5.8.0) is a banking software RCE that can lead to SYSTEM-level compromise. Public PoC exists. Full analysis: https://github.com/alan-turing-institute/cyber-threat-observatory/blob/main/reports/2026-04-22/TIER_2_CVE-2018-25272.md #CyberSecurity #BankingSecurity #DPI #CVE

    Post summary

    CVE‑2018‑25272 is a remote code execution flaw in ELBA5 v5.8.0 that allows system‑level compromise, and a public PoC has been released.

    0000069
    45 followersView on X

Explore more