CVE-2026-82971
Received Received - Intake

Command Injection in QVidium Opera11

Vulnerability report for CVE-2026-82971, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-31

Last updated on: 2026-08-31

Assigner: VulDB

Description

A vulnerability was determined in QVidium Opera11 3.3.2a26-Ax4x-opera11. This affects an unknown part of the file /cgi-bin/net_tr.cgi of the component CGI Script. This manipulation of the argument ipaddr causes command injection. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor explains: "QVidium has now closed its doors and no longer will be able to sell products or provide support." This vulnerability only affects products that are no longer supported by the maintainer.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-31
Last Modified
2026-08-31
Generated
2026-09-01
AI Q&A
2026-09-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
qvidium opera11 3.3.2a26-ax4x-opera11

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-77 The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
CWE-74 The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a command injection flaw in QVidium Opera11 3.3.2a26-Ax4x-opera11. It exists in the /cgi-bin/net_tr.cgi CGI script where the ipaddr argument can be manipulated to execute arbitrary commands remotely. The vendor has discontinued the product and no longer provides support.

Detection Guidance

Since QVidium Opera11 is no longer supported and the vendor has closed, detection may be difficult. Check if the affected CGI script /cgi-bin/net_tr.cgi exists on your system. If present, inspect for command injection attempts in logs or unusual network traffic targeting this endpoint.

Impact Analysis

Since this is a remote command injection vulnerability with a CVSS v3.1 score of 10.0, it allows attackers to execute arbitrary commands on the affected system. This could lead to full system compromise, data theft, or unauthorized access. However, the product is no longer supported, so patches are unavailable.

Compliance Impact

This vulnerability allows remote command injection via the ipaddr parameter in the CGI script, which could lead to unauthorized access and data breaches. For GDPR, this could result in unauthorized processing of personal data, violating principles of lawfulness and security. For HIPAA, it may compromise protected health information integrity and confidentiality if exploited.

Mitigation Strategies

Since QVidium Opera11 is no longer supported and the vendor has closed, immediate mitigation involves isolating or removing the affected system from the network. Patch or update is not available. Monitor network traffic for signs of exploitation targeting /cgi-bin/net_tr.cgi with command injection attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-82971. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart