← Back to browse · API

CVE-2021-26472

Severity
CRITICAL
CVSS
10.0
EPSS
0.02459
Risk score
40.86
CISA KEV
No
PoC
No
Published
2021-06-08
Modified
2024-09-16
First seen
2026-08-07
Aliases
EUVD-2021-13277, GHSA-58H6-F6WR-W2HW
Products
n/a:n/a n/a
Sources
euvd EUVD-2021-13277

Description

In VembuBDR before 4.2.0.1 and VembuOffsiteDR before 4.2.0.1 installed on Windows, the http API located at /consumerweb/secure/download.php. Using this command argument an unauthenticated attacker can execute arbitrary OS commands with SYSTEM privileges.

References