Vulnerabilities > Improper Neutralization of Special Elements used in a Command ('Command Injection')

DATE CVE VULNERABILITY TITLE RISK
2022-02-15 CVE-2021-41552 Command Injection vulnerability in Commscope products
CommScope SURFboard SBG6950AC2 9.1.103AA23 devices allow Command Injection.
low complexity
commscope CWE-77
8.8
2022-02-14 CVE-2019-16864 Command Injection vulnerability in Enterprisedt Completeftp Server
CompleteFTPService.exe in the server in EnterpriseDT CompleteFTP before 12.1.4 allows Remote Code Execution by leveraging a Windows user account that has SSH access.
network
low complexity
enterprisedt CWE-77
8.8
2022-02-04 CVE-2021-44247 Command Injection vulnerability in Totolink A3100R Firmware, A720R Firmware and A830R Firmware
Totolink devices A3100R v4.1.2cu.5050_B20200504, A830R v5.9c.4729_B20191112, and A720R v4.1.5cu.470_B20200911 were discovered to contain command injection vulnerability in the function setNoticeCfg.
network
low complexity
totolink CWE-77
critical
9.8
2022-02-04 CVE-2021-44880 Command Injection vulnerability in Dlink Dir-878 Firmware and Dir-882 Firmware
D-Link devices DIR_878 DIR_878_FW1.30B08_Hotfix_02 and DIR_882 DIR_882_FW1.30B06_Hotfix_02 were discovered to contain a command injection vulnerability in the system function.
network
low complexity
dlink CWE-77
critical
9.8
2022-02-04 CVE-2021-44881 Command Injection vulnerability in Dlink Dir-882 Firmware
D-Link device DIR_882 DIR_882_FW1.30B06_Hotfix_02 was discovered to contain a command injection vulnerability in the twsystem function.
network
low complexity
dlink CWE-77
critical
9.8
2022-02-04 CVE-2021-44882 Command Injection vulnerability in Dlink Dir-878 Firmware
D-Link device DIR_878_FW1.30B08_Hotfix_02 was discovered to contain a command injection vulnerability in the twsystem function.
network
low complexity
dlink CWE-77
critical
9.8
2022-02-04 CVE-2021-45733 Command Injection vulnerability in Totolink X5000R Firmware 9.1.0U.6118B20201102
TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to contain a command injection vulnerability in the function NTPSyncWithHost.
network
low complexity
totolink CWE-77
critical
9.8
2022-02-04 CVE-2021-45738 Command Injection vulnerability in Totolink X5000R Firmware 9.1.0U.6118B20201102
TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to contain a command injection vulnerability in the function UploadFirmwareFile.
network
low complexity
totolink CWE-77
critical
9.8
2022-02-04 CVE-2021-45742 Command Injection vulnerability in Totolink A720R Firmware 4.1.5Cu.470B20200911
TOTOLINK A720R v4.1.5cu.470_B20200911 was discovered to contain a command injection vulnerability in the "Main" function.
network
low complexity
totolink CWE-77
critical
9.8
2022-02-04 CVE-2021-45990 Command Injection vulnerability in Tendacn G1 Firmware and G3 Firmware
Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function uploadPicture.
network
low complexity
tendacn CWE-77
critical
9.8