CVE detail
CVE-2019-25268 — CVE-2019-25268
Published 2026-01-08 · Modified 2026-06-17 · Source nvd
CRITICAL
severity
CVSS-derived band
0.0038
EPSS probability
exploitation probability, 30d
31.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
NREL BEopt 2.8.0.0 contains a DLL hijacking vulnerability that allows attackers to load arbitrary libraries by tricking users into opening application files from remote shares. Attackers can exploit insecure library loading of sdl2.dll and libegl.dll by placing malicious libraries on WebDAV or SMB shares to execute unauthorized code.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References