Description
The QVidium Opera11 device (firmware version 2.9.0-Ax4x-opera11) is vulnerable to Remote Code Execution (RCE) due to improper input validation on the /cgi-bin/net_ping.cgi endpoint. An attacker can exploit this vulnerability by sending a specially crafted GET request with a malicious parameter to inject arbitrary commands. These commands are executed with root privileges, allowing attackers to gain full control over the device. This poses a significant security risk to any device running this software.
INFO
Published Date :
2025-11-19T00:00:00.000Z
Last Modified :
2025-11-21T15:55:29.978Z
Source :
mitre
AFFECTED PRODUCTS
The following products are affected by CVE-2025-63213 vulnerability.
| Vendors | Products |
|---|---|
| Qvidium |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2025-63213.