Record summary

CVE-2021-42071 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit and 1 Nuclei template.

Description

In Visual Tools DVR VX16 4.2.28.0, an unauthenticated attacker can achieve remote command execution via shell metacharacters in the cgi-bin/slogin/login.py User-Agent HTTP header.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Mar 6, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Catalogued exploits
1
Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Proofs of concept

1

Catalogued exploits

ExploitDBVisual Tools DVR VX16 4.2.28.0 - OS Command Injection (Unauthenticated)ExploitDB exploitby Andrea D\'UbaldoNot analyzed1 file
ExploitDB

PoC details

Nuclei templates

1
ProjectDiscoveryCRITICALVisual Tools DVR VX16 4.2.28.0 - Unauthenticated OS Command InjectionCVSS 9.8

Visual Tools DVR VX16 4.2.28.0 could allow an unauthenticated, remote attacker to perform command injection attacks against an affected device.

Impact

Successful exploitation of this vulnerability can lead to unauthorized remote code execution, potentially compromising the confidentiality, integrity, and availability of the affected system.

Remediation

Apply the latest security patch or update provided by the vendor to fix the command injection vulnerability in the Visual Tools DVR VX16 4.2.28.0 device.

WeaknessesCWE-78
Authorsgy741
Template tagscve2021cveedbvisualtoolsrceoastinjectionvisual-toolsvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:o:visual-tools:dvr_vx16_firmware:4.2.28.0:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

4