A vulnerability identified as critical has been detected in nordex-online N149 Wind Turbine Web Server up to 4.5 . The impacted element is an unknown function of the file login.php of the component POST Handler . The manipulation of the argument Login leads to sql injection. This vulnerability is referenced as CVE-2018-25333 . Remote exploitation of the attack is possible. Furthermore, an exploit is available.