Andrea D'Ubaldo

2 exploits Active since Oct 2021
CVE-2021-47799 EXPLOITDB MEDIUM text WORKING POC
Visual Tools DVR VX16 <4.2.28 - Privilege Escalation
Visual Tools DVR VX16 version 4.2.28 contains a local privilege escalation vulnerability in its Sudo configuration that allows attackers to gain root access. Attackers can exploit the unsafe Sudo settings by using mount commands to bind a shell, enabling unauthorized system-level privileges.
CVSS 6.2
CVE-2021-42071 EXPLOITDB CRITICAL text WORKING POC
Visual-tools Dvr Vx16 Firmware - OS Command Injection
In Visual Tools DVR VX16 4.2.28.0, an unauthenticated attacker can achieve remote command execution via shell metacharacters in the cgi-bin/slogin/login.py User-Agent HTTP header.
CVSS 9.8