{"api_version":"1","generated_at":"2026-07-23T14:54:59+00:00","cve":"CVE-2021-41419","urls":{"html":"https://cve.report/CVE-2021-41419","api":"https://cve.report/api/cve/CVE-2021-41419.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-41419","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-41419"},"summary":{"title":"CVE-2021-41419","description":"QVIS NVR DVR before 2021-12-13 is vulnerable to Remote Code Execution via Java deserialization.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2022-07-18 00:15:00","updated_at":"2022-07-25 19:58:00"},"problem_types":["CWE-502"],"metrics":[],"references":[{"url":"https://twitter.com/Me9187/status/1414904314368348163","name":"https://twitter.com/Me9187/status/1414904314368348163","refsource":"MISC","tags":[],"title":"Me on Twitter: \"For more detail, This is an unauthenticated RCE in QVIS DVRs via java deserialization, Multiple disclosure attempts were made to QVIS by me and 3rd parties over the past year which were actively ignored. use this template with @pdnuclei https://t.co/CdgpmWwnii… https://t.co/95tihMBIm4\"","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://gist.github.com/Meeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeee/712ac36c8a08e2698e875169442a23a4","name":"https://gist.github.com/Meeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeee/712ac36c8a08e2698e875169442a23a4","refsource":"MISC","tags":[],"title":"CVE-2021-41419 · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://github.com/projectdiscovery/nuclei-templates/blob/master/iot/qvisdvr-deserialization-rce.yaml","name":"https://github.com/projectdiscovery/nuclei-templates/blob/master/iot/qvisdvr-deserialization-rce.yaml","refsource":"MISC","tags":[],"title":"nuclei-templates/qvisdvr-deserialization-rce.yaml at master · projectdiscovery/nuclei-templates · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-41419","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-41419","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2021","cve_id":"41419","vulnerable":"-1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"qvis","cpe5":"dvr","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"41419","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"qvis","cpe5":"dvr_firmware","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"41419","vulnerable":"-1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"qvis","cpe5":"nvr","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"41419","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"qvis","cpe5":"nvr_firmware","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2021-41419","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"QVIS NVR DVR before 2021-12-13 is vulnerable to Remote Code Execution via Java deserialization."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"url":"https://twitter.com/Me9187/status/1414904314368348163","refsource":"MISC","name":"https://twitter.com/Me9187/status/1414904314368348163"},{"url":"https://github.com/projectdiscovery/nuclei-templates/blob/master/iot/qvisdvr-deserialization-rce.yaml","refsource":"MISC","name":"https://github.com/projectdiscovery/nuclei-templates/blob/master/iot/qvisdvr-deserialization-rce.yaml"},{"refsource":"MISC","name":"https://gist.github.com/Meeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeee/712ac36c8a08e2698e875169442a23a4","url":"https://gist.github.com/Meeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeee/712ac36c8a08e2698e875169442a23a4"}]}},"nvd":{"publishedDate":"2022-07-18 00:15:00","lastModifiedDate":"2022-07-25 19:58:00","problem_types":["CWE-502"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"},"exploitabilityScore":3.9,"impactScore":5.9}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"AND","children":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:qvis:dvr_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"2021-12-13","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":false,"cpe23Uri":"cpe:2.3:h:qvis:dvr:-:*:*:*:*:*:*:*","cpe_name":[]}]}],"cpe_match":[]},{"operator":"AND","children":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:qvis:nvr_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"2021-12-13","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":false,"cpe23Uri":"cpe:2.3:h:qvis:nvr:-:*:*:*:*:*:*:*","cpe_name":[]}]}],"cpe_match":[]}]}},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"41419","Ordinal":"217209","Title":"CVE-2021-41419","CVE":"CVE-2021-41419","Year":"2021"},"notes":[{"CveYear":"2021","CveId":"41419","Ordinal":"1","NoteData":"** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.","Type":"Description","Title":null}]}}}