Description
Teradek VidiU Pro 3.0.3 contains a server-side request forgery vulnerability in the management interface that allows attackers to manipulate GET parameters 'url' and 'xml_url'. Attackers can exploit this flaw to bypass firewalls, initiate network enumeration, and potentially trigger external HTTP requests to arbitrary destinations.
Problem types
Server-Side Request Forgery (SSRF)
Product status
3.0.2r31225
2.4.10
Credits
LiquidWorm as Gjoko Krstic of Zero Science Lab
References
www.zeroscience.mk/en/vulnerabilities/ZSL-2018-5461.php
www.exploit-db.com/exploits/44672
www.exploit-db.com/exploits/44672 (ExploitDB-44672)
www.teradek.com (Teradek Product Homepage)
www.zeroscience.mk/en/vulnerabilities/ZSL-2018-5461.php (Zero Science Lab Disclosure (ZSL-2018-5461))
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.