Vulnerabilities > Improper Neutralization of Special Elements used in a Command ('Command Injection')

DATE CVE VULNERABILITY TITLE RISK
2020-04-16 CVE-2019-20688 Command Injection vulnerability in Netgear products
Certain NETGEAR devices are affected by command injection by an authenticated user.
low complexity
netgear CWE-77
6.8
2020-04-15 CVE-2019-20680 Command Injection vulnerability in Netgear products
Certain NETGEAR devices are affected by command injection by an authenticated user.
low complexity
netgear CWE-77
8.0
2020-04-15 CVE-2019-20659 Command Injection vulnerability in Netgear products
Certain NETGEAR devices are affected by command injection by an authenticated user.
network
low complexity
netgear CWE-77
7.2
2020-04-15 CVE-2019-20655 Command Injection vulnerability in Netgear Xr500 Firmware and Xr700 Firmware
Certain NETGEAR devices are affected by command injection by an authenticated user.
local
low complexity
netgear CWE-77
7.8
2020-04-15 CVE-2019-20651 Command Injection vulnerability in Netgear Wac505 Firmware and Wac510 Firmware
Certain NETGEAR devices are affected by command injection by an authenticated user.
local
low complexity
netgear CWE-77
6.7
2020-04-15 CVE-2020-11789 Command Injection vulnerability in Netgear products
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker.
network
low complexity
netgear CWE-77
critical
9.8
2020-04-15 CVE-2020-11770 Command Injection vulnerability in Netgear products
Certain NETGEAR devices are affected by command injection by an authenticated user.
network
low complexity
netgear CWE-77
8.8
2020-04-15 CVE-2020-10514 Command Injection vulnerability in Icatchinc DVR Firmware
iCatch DVR firmware before 20200103 do not validate function parameter properly, resulting attackers executing arbitrary command.
network
low complexity
icatchinc CWE-77
8.8
2020-04-02 CVE-2019-14868 Command Injection vulnerability in multiple products
In ksh version 20120801, a flaw was found in the way it evaluates certain environment variables.
local
low complexity
ksh-project debian apple CWE-77
7.8
2020-04-01 CVE-2018-11106 Command Injection vulnerability in Netgear products
NETGEAR has released fixes for a pre-authentication command injection in request_handler.php security vulnerability on the following product models: WC7500, running firmware versions prior to 6.5.3.5; WC7520, running firmware versions prior to 2.5.0.46; WC7600v1, running firmware versions prior to 6.5.3.5; WC7600v2, running firmware versions prior to 6.5.3.5; and WC9500, running firmware versions prior to 6.5.3.5.
network
low complexity
netgear CWE-77
critical
9.8