Vulnerabilities > Improper Neutralization of Special Elements used in a Command ('Command Injection')

DATE CVE VULNERABILITY TITLE RISK
2023-08-21 CVE-2023-39617 Command Injection vulnerability in Totolink X5000R Firmware 9.1.0Cu.2089B20211224/9.1.0Cu.2350B20230313
TOTOLINK X5000R_V9.1.0cu.2089_B20211224 and X5000R_V9.1.0cu.2350_B20230313 were discovered to contain a remote code execution (RCE) vulnerability via the lang parameter in the setLanguageCfg function.
network
low complexity
totolink CWE-77
critical
9.8
2023-08-21 CVE-2023-39618 Command Injection vulnerability in Totolink X5000R Firmware B20210419
TOTOLINK X5000R B20210419 was discovered to contain a remote code execution (RCE) vulnerability via the setTracerouteCfg interface.
network
low complexity
totolink CWE-77
critical
9.8
2023-08-21 CVE-2023-39809 Command Injection vulnerability in Nvki Intelligent Broadband Subscriber Gateway 3.5
N.V.K.INTER CO., LTD.
network
low complexity
nvki CWE-77
critical
9.8
2023-08-17 CVE-2023-38902 Command Injection vulnerability in Ruijie products
A command injection vulnerability in RG-EW series home routers and repeaters v.EW_3.0(1)B11P219, RG-NBS and RG-S1930 series switches v.SWITCH_3.0(1)B11P219, RG-EG series business VPN routers v.EG_3.0(1)B11P219, EAP and RAP series wireless access points v.AP_3.0(1)B11P219, and NBC series wireless controllers v.AC_3.0(1)B11P219 allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /cgi-bin/luci/api/cmd via the remoteIp field.
network
low complexity
ruijie CWE-77
8.8
2023-08-17 CVE-2023-2910 Command Injection vulnerability in Asustor Data Master
Improper neutralization of special elements used in a command ('Command Injection') vulnerability in Printer service functionality in ASUSTOR Data Master (ADM) allows remote unauthorized users to execute arbitrary commands via unspecified vectors.
network
low complexity
asustor CWE-77
8.8
2023-08-17 CVE-2023-34215 Command Injection vulnerability in Moxa Tn-5900 Firmware 3.1/3.2/3.3
TN-5900 Series firmware versions v3.3 and prior are vulnerable to the command-injection vulnerability.
network
low complexity
moxa CWE-77
critical
9.8
2023-08-17 CVE-2023-33238 Command Injection vulnerability in Moxa Tn-4900 Firmware and Tn-5900 Firmware
TN-4900 Series firmware versions v1.2.4 and prior and TN-5900 Series firmware versions v3.3 and prior are vulnerable to the command injection vulnerability.
network
low complexity
moxa CWE-77
critical
9.8
2023-08-17 CVE-2023-33239 Command Injection vulnerability in Moxa Tn-4900 Firmware and Tn-5900 Firmware
TN-4900 Series firmware versions v1.2.4 and prior and TN-5900 Series firmware versions v3.3 and prior are vulnerable to the command injection vulnerability.
network
low complexity
moxa CWE-77
critical
9.8
2023-08-17 CVE-2023-34213 Command Injection vulnerability in Moxa Tn-5900 Firmware 3.1/3.2/3.3
TN-5900 Series firmware versions v3.3 and prior are vulnerable to command-injection vulnerability.
network
low complexity
moxa CWE-77
critical
9.8
2023-08-17 CVE-2023-34214 Command Injection vulnerability in Moxa Tn-4900 Firmware and Tn-5900 Firmware
TN-4900 Series firmware versions v1.2.4 and prior and TN-5900 Series firmware versions v3.3 and prior are vulnerable to the command-injection vulnerability.
network
low complexity
moxa CWE-77
critical
9.8