Vulnerabilities > Improper Neutralization of Special Elements used in a Command ('Command Injection')

DATE CVE VULNERABILITY TITLE RISK
2023-05-11 CVE-2023-31528 Command Injection vulnerability in Motorola Cx2L Firmware 1.0.1
Motorola CX2L Router 1.0.1 was discovered to contain a command injection vulnerability via the staticroute_list parameter.
network
low complexity
motorola CWE-77
8.8
2023-05-11 CVE-2023-31529 Command Injection vulnerability in Motorola Cx2L Firmware 1.0.1
Motorola CX2L Router 1.0.1 was discovered to contain a command injection vulnerability via the system_time_timezone parameter.
network
low complexity
motorola CWE-77
8.8
2023-05-11 CVE-2023-31530 Command Injection vulnerability in Motorola Cx2L Firmware 1.0.1
Motorola CX2L Router 1.0.1 was discovered to contain a command injection vulnerability via the smartqos_priority_devices parameter.
network
low complexity
motorola CWE-77
8.8
2023-05-11 CVE-2023-31531 Command Injection vulnerability in Motorola Cx2L Firmware 1.0.1
Motorola CX2L Router 1.0.1 was discovered to contain a command injection vulnerability via the tomography_ping_number parameter.
network
low complexity
motorola CWE-77
8.8
2023-05-11 CVE-2023-31473 Command Injection vulnerability in Gl-Inet products
An issue was discovered on GL.iNet devices before 3.216.
network
low complexity
gl-inet CWE-77
4.9
2023-05-11 CVE-2023-2647 Command Injection vulnerability in Weaver E-Office 9.5
A vulnerability was found in Weaver E-Office 9.5 and classified as critical.
network
low complexity
weaver CWE-77
8.8
2023-05-11 CVE-2023-2649 Command Injection vulnerability in Tenda Ac23 Firmware 16.03.07.45Cn
A vulnerability was found in Tenda AC23 16.03.07.45_cn.
network
low complexity
tenda CWE-77
8.8
2023-05-10 CVE-2022-29842 Command Injection vulnerability in Westerndigital MY Cloud OS
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability that could allow an attacker to execute code in the context of the root user on a vulnerable CGI file was discovered in Western Digital My Cloud OS 5 devicesThis issue affects My Cloud OS 5: before 5.26.119.
network
low complexity
westerndigital CWE-77
critical
9.8
2023-05-10 CVE-2023-30353 Command Injection vulnerability in Tenda CP3 Firmware 11.10.00.2211041355
Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 allows unauthenticated remote code execution via an XML document.
network
low complexity
tenda CWE-77
critical
9.8
2023-05-09 CVE-2023-31476 Command Injection vulnerability in Gl-Inet Gl-Mv1000 Firmware and Gl-Mv1000W Firmware
An issue was discovered on GL.iNet devices running firmware before 3.216.
network
low complexity
gl-inet CWE-77
7.5