Cyber & AI intelligence
Wasteland.
Briefs indexed2354
Issues26
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-82971 2026-08-31

CVE-2026-82971: Unauthenticated Command Injection in QVidium Opera11 (No Patch Expected)

"A publicly disclosed command injection flaw in the QVidium Opera11 CGI interface allows unauthenticated remote attackers to execute commands, and the vendor has shut down, so a fix is unlikely to be released."

A publicly disclosed command injection flaw in the QVidium Opera11 CGI interface allows unauthenticated remote attackers to execute commands, and the vendor has shut down, so a fix is unlikely to be released.

What Is It

CVE-2026-82971 is a command injection vulnerability (CWE-74, CWE-77) in QVidium Opera11, version 3.3.2a26-Ax4x-opera11. The flaw sits in the file /cgi-bin/net_tr.cgi within the device's CGI Script component. Manipulation of the ipaddr argument causes command injection, and the attack can be initiated remotely. According to the NVD record, the exploit has been publicly disclosed and may be utilized.

Why It Matters

The CVSS v3.1 base score is 10.0 (CRITICAL), vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H, network-reachable, low complexity, no privileges, no user interaction, with a changed scope and complete impact to confidentiality, integrity, and availability. The CVSS v4.0 assessment from the CNA rates it 9.3 (CRITICAL) with exploit maturity listed as Proof-of-Concept. In practical terms, anyone who can reach the CGI endpoint over the network can run commands, and public disclosure means the barrier to attempting it is low.

There is no CISA KEV entry for this CVE in the Known Exploited Vulnerabilities catalog, so active in-the-wild exploitation is not confirmed; only public disclosure of the exploit.

What's Vulnerable

The CVE is tagged unsupported-when-assigned, and the record states the vulnerability only affects products no longer supported by the maintainer.

Patch Status

No patch is available, and none appears likely given the vendor's status. The vendor statement quoted in the NVD record is explicit: "QVidium has now closed its doors and no longer will be able to sell products or provide support." No required-action deadline is present in the supplied data, since there is no KEV entry. With an end-of-life product carrying an unauthenticated 10.0 flaw, retirement or network isolation of affected devices is the primary mitigation the source material supports.

Sources