Impact
A vulnerability allows an attacker to inject arbitrary shell commands by manipulating the ipaddr argument in the /cgi-bin/net_tr.cgi CGI script on QVidium Opera11 firmware version 3.3.2a26-Ax4x-opera11. The injection can be performed remotely over the Internet, and the exploit has already been publicly disclosed. Successful exploitation grants the attacker full control over the affected device and its underlying operating system.
Affected Systems
The only listed affected product is QVidium Opera11 firmware 3.3.2a26-Ax4x-opera11. No other vendors, products, or version details are provided. The device is no longer maintained by its vendor, and therefore no vendor patch exists.
Risk and Exploitability
The CVSS score is 10, indicating critical severity. The EPSS score is not available, but the vulnerability is known to be exploitable and has been publicly disclosed. It is not listed in the CISA KEV catalog. Attackers can trigger the command injection by sending a crafted HTTP request with a malicious ipaddr value to /cgi-bin/net_tr.cgi from any network with access to the device, enabling arbitrary command execution and full system compromise.
OpenCVE Enrichment