CVE-2021-42071
72Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actepss 70%
from disclosure to weapon8 days
Published on NVDOct 7
1st PoC+8d
VulnCheck+881d
exploitation probability
70%top 1% of all CVEs
observed exploitation
yesVulnCheck
2 public exploit(s)
In Visual Tools DVR VX16 4.2.28.0, an unauthenticated attacker can achieve remote command execution via shell metacharacters in the cgi-bin/slogin/login.py User-Agent HTTP header.
Affected products
n/a · n/apublic PoCs found — 2
cve_referencewww.exploit-db.com/exploits/50098unverifiedgithubgithub.com/adubaldo/CVE-2021-42071★ 0⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.