CVE-2021-42071
visual-tools dvr_vx16_firmware Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Record summary
CVE-2021-42071 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit and 1 Nuclei template.
Description
In Visual Tools DVR VX16 4.2.28.0, an unauthenticated attacker can achieve remote command execution via shell metacharacters in the cgi-bin/slogin/login.py User-Agent HTTP header.
Exploitation context
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
dvr_vx16_firmwareBrowse visual-tools / dvr_vx16_firmware | VulnCheck | Version data not supplied | |
Proofs of concept
1Catalogued exploits
ExploitDBVisual Tools DVR VX16 4.2.28.0 - OS Command Injection (Unauthenticated)ExploitDB exploitby Andrea D\'UbaldoNot analyzed1 file
Nuclei templates
1ProjectDiscoveryCRITICALVisual Tools DVR VX16 4.2.28.0 - Unauthenticated OS Command InjectionCVSS 9.8
Visual Tools DVR VX16 4.2.28.0 could allow an unauthenticated, remote attacker to perform command injection attacks against an affected device.
Impact
Successful exploitation of this vulnerability can lead to unauthorized remote code execution, potentially compromising the confidentiality, integrity, and availability of the affected system.
Remediation
Apply the latest security patch or update provided by the vendor to fix the command injection vulnerability in the Visual Tools DVR VX16 4.2.28.0 device.
Source: ProjectDiscovery