SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-82971

CRITICAL · CVSS 10 EPSS 1.88% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-31 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

A critical command injection vulnerability exists in the CGI Script component of QVidium Opera11 3.3.2a26-Ax4x-opera11, allowing remote attackers to manipulate the 'ipaddr' argument. Given that QVidium has ceased operations and no longer provides support or updates, organizations using affected products should prioritize remediation efforts to mitigate potential exploitation. Immediate action is essential for any users still operating these unsupported systems to safeguard against potential attacks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-82971
Severity
CRITICAL
CVSS
10
EPSS
1.88%

Original NVD Description

A vulnerability was determined in QVidium Opera11 3.3.2a26-Ax4x-opera11. This affects an unknown part of the file /cgi-bin/net_tr.cgi of the component CGI Script. This manipulation of the argument ipaddr causes command injection. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor explains: "QVidium has now closed its doors and no longer will be able to sell products or provide support." This vulnerability only affects products that are no longer supported by the maintainer.