Vulnerabilities > Improper Neutralization of Special Elements used in a Command ('Command Injection')

DATE CVE VULNERABILITY TITLE RISK
2022-02-04 CVE-2021-44882 Command Injection vulnerability in Dlink Dir-878 Firmware
D-Link device DIR_878_FW1.30B08_Hotfix_02 was discovered to contain a command injection vulnerability in the twsystem function.
network
low complexity
dlink CWE-77
critical
9.8
2022-02-04 CVE-2021-45733 Command Injection vulnerability in Totolink X5000R Firmware 9.1.0U.6118B20201102
TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to contain a command injection vulnerability in the function NTPSyncWithHost.
network
low complexity
totolink CWE-77
critical
9.8
2022-02-04 CVE-2021-45738 Command Injection vulnerability in Totolink X5000R Firmware 9.1.0U.6118B20201102
TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to contain a command injection vulnerability in the function UploadFirmwareFile.
network
low complexity
totolink CWE-77
critical
9.8
2022-02-04 CVE-2021-45742 Command Injection vulnerability in Totolink A720R Firmware 4.1.5Cu.470B20200911
TOTOLINK A720R v4.1.5cu.470_B20200911 was discovered to contain a command injection vulnerability in the "Main" function.
network
low complexity
totolink CWE-77
critical
9.8
2022-02-04 CVE-2021-45990 Command Injection vulnerability in Tendacn G1 Firmware and G3 Firmware
Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function uploadPicture.
network
low complexity
tendacn CWE-77
critical
9.8
2022-02-04 CVE-2021-45998 Command Injection vulnerability in Dlink Dir-882 Firmware
D-Link device DIR_882 DIR_882_FW1.30B06_Hotfix_02 was discovered to contain a command injection vulnerability in the LocalIPAddress parameter.
network
low complexity
dlink CWE-77
critical
9.8
2022-02-04 CVE-2021-46226 Command Injection vulnerability in Dlink Di-7200Gv2 Firmware 21.04.09E1
D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function wget_test.asp.
network
low complexity
dlink CWE-77
critical
9.8
2022-02-04 CVE-2021-46227 Command Injection vulnerability in Dlink Di-7200Gv2 Firmware 21.04.09E1
D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function proxy_client.asp.
network
low complexity
dlink CWE-77
critical
9.8
2022-02-04 CVE-2021-46228 Command Injection vulnerability in Dlink Di-7200Gv2 Firmware 21.04.09E1
D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function httpd_debug.asp.
network
low complexity
dlink CWE-77
critical
9.8
2022-02-04 CVE-2021-46229 Command Injection vulnerability in Dlink Di-7200Gv2 Firmware 21.04.09E1
D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function usb_paswd.asp.
network
low complexity
dlink CWE-77
critical
9.8