---
id: CVE-2019-25718
title: >-
  Dräger Infinity Explorer C700 contains a privilege escalation vulnerability
  that allows attackers to break out of kiosk mode and access the underlying
  operating system through a specific dialog interaction
summary: >-
  Dräger Infinity Explorer C700 contains a privilege escalation vulnerability
  that allows attackers to break out of kiosk mode and access the underlying
  operating system through a specific dialog interaction. Attackers can exploit
  this kio…
severity: high
cvss: 8.4
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-451
vendor: draeger
product: infinity_explorer_c700_firmware
affected:
  - infinity_explorer_c700_firmware
published: '2026-06-01'
updated: '2026-06-30'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2019-25718'
references:
  - url: >-
      https://static.draeger.com/security/download/2019-01-22-draeger-infinity-delta-vf10-1-security-advisory.pdf
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/dr-ger-infinity-explorer-c700-privilege-escalation-via-kiosk-mode-bypass
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.00118
epssPercentile: 0.01927
ingestedAt: '2026-07-01T09:50:45.886Z'
---

## Overview

Dräger Infinity Explorer C700 contains a privilege escalation vulnerability that allows attackers to break out of kiosk mode and access the underlying operating system through a specific dialog interaction. Attackers can exploit this kiosk escape to take control of the operating system and cause the device to display incorrect or no information from the connected Delta Family patient monitor.

## Affected

- `infinity_explorer_c700_firmware`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
