Critical severity10.0NVD Advisory· Published Jun 8, 2021· Updated Jun 17, 2026
CVE-2021-26472
CVE-2021-26472
Description
In VembuBDR before 4.2.0.1 and VembuOffsiteDR before 4.2.0.1 installed on Windows, the http API located at /consumerweb/secure/download.php. Using this command argument an unauthenticated attacker can execute arbitrary OS commands with SYSTEM privileges.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Vembu/VembuBDRdescription
- Range: <4.2.0.1
Patches
Vulnerability mechanics
References
4- csirt.divd.nl/2021/05/11/Vembu-zero-days/nvdThird Party Advisory
- csirt.divd.nl/cases/DIVD-2020-00011/nvdThird Party Advisory
- csirt.divd.nl/cves/CVE-2021-26472/nvdThird Party Advisory
- www.wbsec.nl/vembunvdBroken LinkThird Party Advisory
News mentions
0No linked articles in our index yet.