CVE-2021-42071 | Visual Tools DVR VX16 4.2.28.0 HTTP Header cgi-bin/slogin/login.py User-Agent os command injection (Exploit 50098 / EDB-50098)
A vulnerability, which was classified as critical, was found in Visual Tools DVR VX16 4.2.28.0. Affected is an unknown function of the file cgi-bin/slogin/login.py of the component HTTP Header Handler. The manipulation of the argument User-Agent leads to os command injection.
This vulnerability is traded as CVE-2021-42071. It is possible to launch the attack remotely. Furthermore, there is an exploit available.