Qvidium's vulnerability footprint centers on a narrow line of set-top box and middleware products including the Amino A140 and Opera11 platforms, which are deployed in broadcast and IPTV delivery infrastructure. The recurring weakness classes—improper input validation and command injection—reflect the attack surface inherent to internet-connected media devices that parse and process untrusted streaming data and control signals. Current severity, exploitation, and exposure figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Qvidium over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-63213CRITICAL The QVidium Opera11 device (firmware version 2.9.0-Ax4x-opera11) is vulnerable to Remote Code Execution (RCE) due to improper input validation on the /cgi-bin/net_ping.cgi endpoint | Nov 19, 2025 | 9.8 | 30 | NO | NO |
CVE-2022-40021CRITICAL QVidium Technologies Amino A140 (prior to firmware version 1.0.0-283) was discovered to contain a command injection vulnerability. | Feb 17, 2023 | 9.8 | 30 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Qvidium.
Media articles that mention a CVE ID that affects a product developed by Qvidium — matched by CVE ID, not by vendor name.