CVE-2018-25159CWE-1334

Epross AVCON6 OGNL Remote Code Execution via login.action

Critical · published March 11, 2026

CVSS v4.0
9.3
EPSS
0%
Percentile
32.6
In the wild
Unconfirmed
What it is

Epross AVCON6 systems management platform contains an object-graph navigation language (OGNL) injection vulnerability that allows unauthenticated attackers to execute arbitrary commands by injecting malicious OGNL expressions. Attackers can send crafted requests to the login.action endpoint with OGNL payloads in the redirect parameter to instantiate ProcessBuilder objects and execute system commands with root privileges.

The record
Technical detail
CVSS v4.0
9.3 · CRITICAL
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS
0.00394 · 32.6th percentile
Weakness
CWE-1334 · Unauthorized Error Injection Can Degrade Hardware Redundancy
Published
2026-03-11T18:23Z
EPSS history
Timeline
  • 11 MAR 18:23Z
    Epross AVCON6 OGNL Remote Code Execution via login.action
    cvelistv5