Description
A vulnerability was determined in QVidium Opera11 3.3.2a26-Ax4x-opera11. This affects an unknown part of the file /cgi-bin/net_tr.cgi of the component CGI Script. This manipulation of the argument ipaddr causes command injection. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor explains: "QVidium has now closed its doors and no longer will be able to sell products or provide support." This vulnerability only affects products that are no longer supported by the maintainer.
Published: 2026-08-31
Score: 10 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability allows an attacker to inject arbitrary shell commands by manipulating the ipaddr argument in the /cgi-bin/net_tr.cgi CGI script on QVidium Opera11 firmware version 3.3.2a26-Ax4x-opera11. The injection can be performed remotely over the Internet, and the exploit has already been publicly disclosed. Successful exploitation grants the attacker full control over the affected device and its underlying operating system.

Affected Systems

The only listed affected product is QVidium Opera11 firmware 3.3.2a26-Ax4x-opera11. No other vendors, products, or version details are provided. The device is no longer maintained by its vendor, and therefore no vendor patch exists.

Risk and Exploitability

The CVSS score is 10, indicating critical severity. The EPSS score is not available, but the vulnerability is known to be exploitable and has been publicly disclosed. It is not listed in the CISA KEV catalog. Attackers can trigger the command injection by sending a crafted HTTP request with a malicious ipaddr value to /cgi-bin/net_tr.cgi from any network with access to the device, enabling arbitrary command execution and full system compromise.

Generated by OpenCVE AI on August 31, 2026 at 23:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Identify whether the device is still in operation and exposed to external networks; if so, block or restrict access to the /cgi-bin/net_tr.cgi URI via firewall rules or ACLs.
  • Replace the unsupported QVidium Opera11 firmware with a supported platform or updated firmware that has removed the vulnerable CGI script, if a replacement exists.
  • Monitor web server logs for attempts to inject commands through the ipaddr parameter and set up alerts for repeated or anomalous access to the net_tr.cgi endpoint.

Generated by OpenCVE AI on August 31, 2026 at 23:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 31 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Qvidium opera11
Vendors & Products Qvidium opera11

Mon, 31 Aug 2026 22:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was determined in QVidium Opera11 3.3.2a26-Ax4x-opera11. This affects an unknown part of the file /cgi-bin/net_tr.cgi of the component CGI Script. This manipulation of the argument ipaddr causes command injection. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor explains: "QVidium has now closed its doors and no longer will be able to sell products or provide support." This vulnerability only affects products that are no longer supported by the maintainer.
Title QVidium Opera11 CGI Script net_tr.cgi command injection
First Time appeared Qvidium
Qvidium opera11 Firmware
Weaknesses CWE-74
CWE-77
CPEs cpe:2.3:o:qvidium:opera11_firmware:*:*:*:*:*:*:*:*
Vendors & Products Qvidium
Qvidium opera11 Firmware
References
Metrics cvssV2_0

{'score': 10, 'vector': 'AV:N/AC:L/Au:N/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 10, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 10, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P'}


Subscriptions

Qvidium Opera11 Opera11 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-31T22:15:39.929Z

Reserved: 2026-08-31T14:23:57.575Z

Link: CVE-2026-82971

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-31T23:16:35.460

Modified: 2026-08-31T23:16:35.460

Link: CVE-2026-82971

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-31T23:30:06Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')