Summary
CVE-2026-82971 is a critical, unauthenticated OS command injection vulnerability in QVidium Opera11 firmware version 3.3.2a26-Ax4x-opera11. The flaw resides in the /cgi-bin/net_tr.cgi CGI script and allows a remote, unauthenticated attacker to execute arbitrary commands on the device by manipulating the ipaddr parameter. The issue has been assigned a CVSS score of 10.0 (Critical), and a public exploit is available; QVidium has ceased operations and is not expected to release a fix.
Technical details
- Root cause: Improper sanitization of user-supplied input in the
ipaddrparameter processed by the/cgi-bin/net_tr.cgiCGI script, allowing shell metacharacters to be injected and executed by the underlying OS. - Trigger conditions: An attacker sends a crafted HTTP request to the
net_tr.cgiendpoint with a maliciousipaddrvalue; no authentication or user interaction is required. - Attack vector: Network — the vulnerable CGI endpoint is exposed over the device’s management web interface.
- Impact: Full compromise of confidentiality, integrity, and availability of the device, including arbitrary command execution with the privileges of the web service process.
Affected software
- QVidium Opera11 firmware, version 3.3.2a26-Ax4x-opera11
Severity
- CVSS v3.1 Base Score: 10.0 (Critical)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: No vendor patch is available. QVidium has ceased operations and no longer provides support or updates for this product.
- Workarounds/network mitigations:
- Remove affected devices from direct internet exposure; restrict access to the management web interface (including
/cgi-bin/net_tr.cgi) to trusted internal networks only, via firewall rules or network segmentation. - Place devices behind a VPN or access-controlled gateway rather than exposing the CGI interface publicly.
- Monitor for unusual requests to
/cgi-bin/net_tr.cgior anomalous outbound connections/process activity on the device. - Given the vendor’s closure and lack of ongoing support, plan for replacement of affected devices with a supported alternative.
- Remove affected devices from direct internet exposure; restrict access to the management web interface (including
How IONIX identifies potentially affected assets
IONIX matches the following signals against data already collected when it crawled the asset; identifying the technology sends no request beyond that crawl.
- Page title:
QVidium Management

