Vulnerabilities > Improper Neutralization of Special Elements used in a Command ('Command Injection')

DATE CVE VULNERABILITY TITLE RISK
2023-08-16 CVE-2023-20237 Command Injection vulnerability in Cisco Intersight Virtual Appliance
A vulnerability in Cisco Intersight Virtual Appliance could allow an unauthenticated, adjacent attacker to access internal HTTP services that are otherwise inaccessible. This vulnerability is due to insufficient restrictions on internally accessible http proxies.
low complexity
cisco CWE-77
4.3
2023-08-16 CVE-2023-20209 Command Injection vulnerability in Cisco Telepresence Video Communication Server 14.0/14.0.5/14.0.7
A vulnerability in the web-based management interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker with read-write privileges on the application to perform a command injection attack that could result in remote code execution on an affected device. This vulnerability is due to insufficient validation of user-supplied input.
network
low complexity
cisco CWE-77
7.2
2023-08-15 CVE-2023-38864 Command Injection vulnerability in Comfast Cf-Xr11 Firmware 2.7.2
An issue in COMFAST CF-XR11 v.2.7.2 allows an attacker to execute arbitrary code via the protal_delete_picname parameter in the sub_41171C function at bin/webmgnt.
network
low complexity
comfast CWE-77
critical
9.8
2023-08-15 CVE-2023-38866 Command Injection vulnerability in Comfast Cf-Xr11 Firmware 2.7.2
COMFAST CF-XR11 V2.7.2 has a command injection vulnerability detected at function sub_415588.
network
low complexity
comfast CWE-77
critical
9.8
2023-08-15 CVE-2023-38861 Command Injection vulnerability in Wavlink Wl-Wn575A3 Firmware R75A3V1410220513
An issue in Wavlink WL_WNJ575A3 v.R75A3_V1410_220513 allows a remote attacker to execute arbitrary code via username parameter of the set_sys_adm function in adm.cgi.
network
low complexity
wavlink CWE-77
critical
9.8
2023-08-15 CVE-2023-38862 Command Injection vulnerability in Comfast Cf-Xr11 Firmware 2.7.2
An issue in COMFAST CF-XR11 v.2.7.2 allows an attacker to execute arbitrary code via the destination parameter of sub_431F64 function in bin/webmgnt.
network
low complexity
comfast CWE-77
critical
9.8
2023-08-15 CVE-2023-38863 Command Injection vulnerability in Comfast Cf-Xr11 Firmware 2.7.2
An issue in COMFAST CF-XR11 v.2.7.2 allows an attacker to execute arbitrary code via the ifname and mac parameters in the sub_410074 function at bin/webmgnt.
network
low complexity
comfast CWE-77
critical
9.8
2023-08-15 CVE-2023-38865 Command Injection vulnerability in Comfast Cf-Xr11 Firmware 2.7.2
COMFAST CF-XR11 V2.7.2 has a command injection vulnerability detected at function sub_4143F0.
network
low complexity
comfast CWE-77
critical
9.8
2023-08-14 CVE-2023-39293 Command Injection vulnerability in Mitel products
A Command Injection vulnerability has been identified in the MiVoice Office 400 SMB Controller through 1.2.5.23 which could allow a malicious actor to execute arbitrary commands within the context of the system.
network
low complexity
mitel CWE-77
critical
9.8
2023-08-14 CVE-2023-40293 Command Injection vulnerability in Samsung Harman Infotainment 20190525031613
Harman Infotainment 20190525031613 and later allows command injection via unauthenticated RPC with a D-Bus connection object.
low complexity
samsung CWE-77
6.8