ZeroHour

CVE-2026-82971

niche

Unauthenticated Command Injection in QVidium Opera11 Streaming Appliance

CVSS 4.0
9.3 critical
EPSS
2%p78
Published
()
Modified
AI analysis

QVidium Opera11 version 3.3.2a26-Ax4x-opera11 contains a command injection flaw in the CGI script /cgi-bin/net_tr.cgi, where the 'ipaddr' argument is passed to the system without proper sanitization (CWE-74/CWE-77). An attacker who can reach the appliance's web interface over the network can send a crafted 'ipaddr' value to execute arbitrary operating-system commands; the CVSS 4.0 score of 9.3 reflects no privileges or user interaction required and high impact on the device's confidentiality, integrity, and availability, as well as on connected systems. Successful exploitation effectively grants remote code execution on the appliance, which is typically used as a network video streaming endpoint. Only QVidium Opera11 is affected, and the vendor has gone out of business, so no fixed version or official support is available. The exploit has been publicly disclosed and may be utilized (EPSS estimates a 1.9% chance of exploitation within 30 days, percentile 78); the issue is not yet listed in CISA KEV and no PoC is catalogued in this feed.

What to do: No patch is forthcoming because QVidium is no longer in business, so mitigation must be network-based: restrict access to the appliance's management/web interface (the /cgi-bin/net_tr.cgi endpoint) with firewall rules or ACLs and avoid exposing it to the internet. Check whether any Opera11 units are internet-reachable and whether net_tr.cgi responds to unauthenticated requests. Plan replacement or isolation of these end-of-life appliances, since they will receive no security updates.

Affected
QVidium Opera113.3.2a26-Ax4x-opera11 (all units running this CGI-based firmware line; vendor is defunct and no fixed version exists)
Estimated exposure
nichelikely hundreds to low thousands of deployed appliances worldwide — QVidium was a niche streaming-hardware vendor that has shut down, and these specialized video-streaming appliances were deployed mainly in point-to-point broadcast/enterprise streaming setups, implying a small installed base in the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability was determined in QVidium Opera11 3.3.2a26-Ax4x-opera11. This affects an unknown part of the file /cgi-bin/net_tr.cgi of the component CGI Script. This manipulation of the argument ipaddr causes command injection. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor explains: "QVidium has now closed its doors and no longer will be able to sell products or provide support." This vulnerability only affects products that are no longer supported by the maintainer.

Weakness
CWE-74, CWE-77
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.