Critical severity9.8NVD Advisory· Published Jun 8, 2021· Updated Jun 17, 2026
CVE-2021-26471
CVE-2021-26471
Description
In VembuBDR before 4.2.0.1 and VembuOffsiteDR before 4.2.0.1, the http API located at /sgwebservice_o.php accepts a command argument. Using this command argument an unauthenticated attacker can execute arbitrary shell commands.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Vembu/VembuBDRdescription
- Range: <4.2.0.1
Patches
Vulnerability mechanics
References
4- csirt.divd.nl/2021/05/11/Vembu-zero-days/nvdThird Party Advisory
- csirt.divd.nl/cases/DIVD-2020-00011/nvdThird Party Advisory
- csirt.divd.nl/cves/CVE-2021-26471/nvdThird Party Advisory
- www.wbsec.nl/vembunvdBroken LinkThird Party Advisory
News mentions
0No linked articles in our index yet.