Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-82971: QVidium Opera11 allows remote command execution via net_tr.cgi

CVE-2026-82971 · published 2 days ago
Summary

The web component net_tr.cgi in QVidium Opera11 can be tricked into running commands you did not intend by sending a specially crafted IP address value. This can be done from anywhere on the internet and could let an attacker take control of the server. The product is no longer sold or supported, so the safest step is to remove the software or isolate the server from the network.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
qvidium opera11 3.3.2a26-Ax4x-opera11
Original advisory text
A vulnerability was determined in QVidium Opera11 3.3.2a26-Ax4x-opera11. This affects an unknown part of the file /cgi-bin/net_tr.cgi of the component CGI Script. This manipulation of the argument ...
A vulnerability was determined in QVidium Opera11 3.3.2a26-Ax4x-opera11. This affects an unknown part of the file /cgi-bin/net_tr.cgi of the component CGI Script. This manipulation of the argument ipaddr causes command injection. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor explains: "QVidium has now closed its doors and no longer will be able to sell products or provide support." This vulnerability only affects products that are no longer supported by the maintainer.
Severity
9.3 Critical
CVSS 3.1: 10.0 (MITRE)
Exploitation
EPSS 2%
Type
CWE-77Command Injection
CWE-74Injection
Timeline
Published31 Aug 2026
Updated1 Sep 2026
First seen31 Aug 2026
Sources
CVE-2026-82971 · MITRE
Monitor software like this
Free during beta