← Back to browse · API

CVE-2021-26471

Severity
CRITICAL
CVSS
9.8
EPSS
0.02261
Risk score
39.99
CISA KEV
No
PoC
No
Published
2021-06-08
Modified
2024-09-16
First seen
2026-08-07
Aliases
EUVD-2021-13276, GHSA-RPCC-JVGM-8VRR
Products
n/a:n/a n/a
Sources
euvd EUVD-2021-13276

Description

In VembuBDR before 4.2.0.1 and VembuOffsiteDR before 4.2.0.1, the http API located at /sgwebservice_o.php accepts a command argument. Using this command argument an unauthenticated attacker can execute arbitrary shell commands.

References