Vulnerabilities > Improper Neutralization of Special Elements used in a Command ('Command Injection')

DATE CVE VULNERABILITY TITLE RISK
2020-09-08 CVE-2020-11117 Command Injection vulnerability in Qualcomm products
u'In the lbd service, an external user can issue a specially crafted debug command to overwrite arbitrary files with arbitrary content resulting in remote code execution.' in Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Wired Infrastructure and Networking in IPQ4019, IPQ6018, IPQ8064, IPQ8074, QCA4531, QCA9531, QCA9980
network
low complexity
qualcomm CWE-77
critical
9.8
2020-09-03 CVE-2020-9199 Command Injection vulnerability in Huawei products
B2368-22 V100R001C00;B2368-57 V100R001C00;B2368-66 V100R001C00 have a command injection vulnerability.
low complexity
huawei CWE-77
6.8
2020-09-02 CVE-2020-25079 Command Injection vulnerability in Dlink Dcs-2530L Firmware and Dcs-2670L Firmware
An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices.
network
low complexity
dlink CWE-77
8.8
2020-09-01 CVE-2020-25067 Command Injection vulnerability in Netgear R8300 Firmware
NETGEAR R8300 devices before 1.0.2.134 are affected by command injection by an unauthenticated attacker.
low complexity
netgear CWE-77
8.8
2020-08-21 CVE-2019-11853 Command Injection vulnerability in Sierrawireless Aleos
Several potential command injections vulnerabilities exist in the AT command interface of ALEOS before 4.11.0, and 4.9.4.
network
low complexity
sierrawireless CWE-77
7.2
2020-08-17 CVE-2020-9242 Command Injection vulnerability in Huawei Fusioncompute 8.0.0
FusionCompute 8.0.0 have a command injection vulnerability.
network
low complexity
huawei CWE-77
8.8
2020-07-29 CVE-2020-7697 Command Injection vulnerability in Mock2Easy Project Mock2Easy
This affects all versions of package mock2easy.
network
low complexity
mock2easy-project CWE-77
critical
9.8
2020-07-28 CVE-2020-13919 Command Injection vulnerability in Ruckuswireless Unleashed Firmware
emfd/libemf in Ruckus Wireless Unleashed through 200.7.10.102.92 allows a remote attacker to achieve command injection via a crafted HTTP request.
network
low complexity
ruckuswireless CWE-77
critical
9.8
2020-07-28 CVE-2020-13917 Command Injection vulnerability in Ruckuswireless Unleashed Firmware
rkscli in Ruckus Wireless Unleashed through 200.7.10.92 allows a remote attacker to achieve command injection and jailbreak the CLI via a crafted CLI command.
network
low complexity
ruckuswireless CWE-77
critical
9.8
2020-07-17 CVE-2020-9688 Command Injection vulnerability in Adobe Download Manager 2.0.0.518
Adobe Download Manager version 2.0.0.518 have a command injection vulnerability.
local
low complexity
adobe CWE-77
7.8