Command Injection Vulnerability in QVidium Opera11 CGI Script
CVE-2026-82971
Key Information:
Badges
What is CVE-2026-82971?
A command injection vulnerability exists in the CGI script located at /cgi-bin/net_tr.cgi in QVidium Opera11 version 3.3.2a26-Ax4x-opera11. This vulnerability can be exploited by manipulating the 'ipaddr' argument, allowing attackers to execute arbitrary commands on the server. Given that QVidium has ceased operations, no patches or support will be provided, leaving affected users at significant risk. The exploit has been made publicly available, raising concerns for organizations still utilizing unsupported versions of this product.
Affected Version(s)
Opera11 3.3.2a26-Ax4x-opera11
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
