CVE-2026-82971
nicheUnauthenticated Command Injection in QVidium Opera11 Streaming Appliance
QVidium Opera11 version 3.3.2a26-Ax4x-opera11 contains a command injection flaw in the CGI script /cgi-bin/net_tr.cgi, where the 'ipaddr' argument is passed to the system without proper sanitization (CWE-74/CWE-77). An attacker who can reach the appliance's web interface over the network can send a crafted 'ipaddr' value to execute arbitrary operating-system commands; the CVSS 4.0 score of 9.3 reflects no privileges or user interaction required and high impact on the device's confidentiality, integrity, and availability, as well as on connected systems. Successful exploitation effectively grants remote code execution on the appliance, which is typically used as a network video streaming endpoint. Only QVidium Opera11 is affected, and the vendor has gone out of business, so no fixed version or official support is available. The exploit has been publicly disclosed and may be utilized (EPSS estimates a 1.9% chance of exploitation within 30 days, percentile 78); the issue is not yet listed in CISA KEV and no PoC is catalogued in this feed.
What to do: No patch is forthcoming because QVidium is no longer in business, so mitigation must be network-based: restrict access to the appliance's management/web interface (the /cgi-bin/net_tr.cgi endpoint) with firewall rules or ACLs and avoid exposing it to the internet. Check whether any Opera11 units are internet-reachable and whether net_tr.cgi responds to unauthenticated requests. Plan replacement or isolation of these end-of-life appliances, since they will receive no security updates.
| QVidium Opera11 | 3.3.2a26-Ax4x-opera11 (all units running this CGI-based firmware line; vendor is defunct and no fixed version exists) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability was determined in QVidium Opera11 3.3.2a26-Ax4x-opera11. This affects an unknown part of the file /cgi-bin/net_tr.cgi of the component CGI Script. This manipulation of the argument ipaddr causes command injection. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor explains: "QVidium has now closed its doors and no longer will be able to sell products or provide support." This vulnerability only affects products that are no longer supported by the maintainer.
- Weakness
- CWE-74, CWE-77
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.