Executive brief
QVidium Opera11 is a network device management interface. The product contains a command injection vulnerability in its CGI script (/cgi-bin/net_tr.cgi) that allows remote attackers to execute arbitrary system commands. Since QVidium ceased operations and no longer provides support or patches, affected devices remain vulnerable.
Technical details
The vulnerability is a command injection flaw in the /cgi-bin/net_tr.cgi CGI script where the ipaddr parameter is not properly sanitized before being used in a system command. An unauthenticated remote attacker can send a crafted HTTP request to the vulnerable endpoint with malicious input in the ipaddr argument to achieve arbitrary command execution with the privileges of the web server process. The attack vector is network-based and requires no authentication. Exploitation is straightforward and proof-of-concept code has been publicly disclosed. The vendor (QVidium) has ceased operations and will not release patches or provide support.
Affected products
- QVidium Opera11 3.3.2a26-Ax4x-opera11
Timeline
- 2026-08-31: disclosed
- 2026-08-31: advisory: Public disclosure announced