In Visual Tools DVR VX16 4.2.28.0, an unauthenticated attacker can achieve remote command execution via shell metacharacters in the cgi-bin/slogin/login.py User-Agent HTTP header.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2021-10-07T16:15:14

Updated: 2024-08-04T03:22:25.941Z

Reserved: 2021-10-07T00:00:00

Link: CVE-2021-42071

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2021-10-07T17:15:08.453

Modified: 2021-10-15T16:11:36.727

Link: CVE-2021-42071

cve-icon Redhat

No data.