Vulnerabilities > Improper Neutralization of Special Elements used in a Command ('Command Injection')

DATE CVE VULNERABILITY TITLE RISK
2023-05-17 CVE-2023-31208 Command Injection vulnerability in multiple products
Improper neutralization of livestatus command delimiters in the RestAPI in Checkmk < 2.0.0p36, < 2.1.0p28, and < 2.2.0b8 (beta) allows arbitrary livestatus command execution for authorized users.
network
low complexity
tribe29 checkmk CWE-77
8.8
2023-05-16 CVE-2023-31856 Command Injection vulnerability in Totolink Cp300+ Firmware 5.2Cu.7594B20200910
A command injection vulnerability in the hostTime parameter in the function NTPSyncWithHostof TOTOLINK CP300+ V5.2cu.7594_B20200910 allows attackers to execute arbitrary commands via a crafted http packet.
network
low complexity
totolink CWE-77
critical
9.8
2023-05-15 CVE-2023-31986 Command Injection vulnerability in Edimax Br-6428Ns Firmware 1.10
A Command Injection vulnerability in Edimax Wireless Router N300 Firmware BR-6428NS_v4 allows attacker to execute arbitrary code via the setWAN function in /bin/webs without any limitations.
network
low complexity
edimax CWE-77
critical
9.8
2023-05-12 CVE-2023-31983 Command Injection vulnerability in Edimax Br-6428Ns Firmware 1.10
A Command Injection vulnerability in Edimax Wireless Router N300 Firmware BR-6428NS_v4 allows attacker to execute arbitrary code via the mp function in /bin/webs without any limitations.
network
low complexity
edimax CWE-77
critical
9.8
2023-05-12 CVE-2023-2682 Command Injection vulnerability in Catontechnology Caton Live 20230426
A vulnerability was found in Caton Live up to 2023-04-26 and classified as critical.
network
low complexity
catontechnology CWE-77
6.3
2023-05-12 CVE-2023-31985 Command Injection vulnerability in Edimax Br-6428Ns Firmware 1.10
A Command Injection vulnerability in Edimax Wireless Router N300 Firmware BR-6428NS_v4 allows attacker to execute arbitrary code via the formAccept function in /bin/webs without any limitations.
network
low complexity
edimax CWE-77
critical
9.8
2023-05-11 CVE-2023-31528 Command Injection vulnerability in Motorola Cx2L Firmware 1.0.1
Motorola CX2L Router 1.0.1 was discovered to contain a command injection vulnerability via the staticroute_list parameter.
network
low complexity
motorola CWE-77
8.8
2023-05-11 CVE-2023-31529 Command Injection vulnerability in Motorola Cx2L Firmware 1.0.1
Motorola CX2L Router 1.0.1 was discovered to contain a command injection vulnerability via the system_time_timezone parameter.
network
low complexity
motorola CWE-77
8.8
2023-05-11 CVE-2023-31530 Command Injection vulnerability in Motorola Cx2L Firmware 1.0.1
Motorola CX2L Router 1.0.1 was discovered to contain a command injection vulnerability via the smartqos_priority_devices parameter.
network
low complexity
motorola CWE-77
8.8
2023-05-11 CVE-2023-31531 Command Injection vulnerability in Motorola Cx2L Firmware 1.0.1
Motorola CX2L Router 1.0.1 was discovered to contain a command injection vulnerability via the tomography_ping_number parameter.
network
low complexity
motorola CWE-77
8.8