Vulnerabilities > Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

DATE CVE VULNERABILITY TITLE RISK
2022-03-15 CVE-2022-26214 OS Command Injection vulnerability in Totolink products
Totolink A830R V5.9c.4729_B20191112, A3100R V4.1.2cu.5050_B20200504, A950RG V4.1.2cu.5161_B20200903, A800R V4.1.2cu.5137_B20200730, A3000RU V5.9c.5185_B20201128, and A810R V4.1.2cu.5182_B20201026 were discovered to contain a command injection vulnerability in the function NTPSyncWithHost.
network
low complexity
totolink CWE-78
critical
9.8
2022-03-15 CVE-2022-26990 OS Command Injection vulnerability in Arris products
Arris routers SBR-AC1900P 1.0.7-B05, SBR-AC3200P 1.0.7-B05 and SBR-AC1200P 1.0.5-B05 were discovered to contain a command injection vulnerability in the firewall-local log function via the EmailAddress, SmtpServerName, SmtpUsername, and SmtpPassword parameters.
network
low complexity
arris CWE-78
critical
9.8
2022-03-15 CVE-2022-26991 OS Command Injection vulnerability in Arris products
Arris routers SBR-AC1900P 1.0.7-B05, SBR-AC3200P 1.0.7-B05 and SBR-AC1200P 1.0.5-B05 were discovered to contain a command injection vulnerability in the ntp function via the TimeZone parameter.
network
low complexity
arris CWE-78
critical
9.8
2022-03-15 CVE-2022-26992 OS Command Injection vulnerability in Arris products
Arris routers SBR-AC1900P 1.0.7-B05, SBR-AC3200P 1.0.7-B05 and SBR-AC1200P 1.0.5-B05 were discovered to contain a command injection vulnerability in the ddns function via the DdnsUserName, DdnsHostName, and DdnsPassword parameters.
network
low complexity
arris CWE-78
critical
9.8
2022-03-15 CVE-2022-26993 OS Command Injection vulnerability in Arris products
Arris routers SBR-AC1900P 1.0.7-B05, SBR-AC3200P 1.0.7-B05 and SBR-AC1200P 1.0.5-B05 were discovered to contain a command injection vulnerability in the pppoe function via the pppoeUserName, pppoePassword, and pppoe_Service parameters.
network
low complexity
arris CWE-78
critical
9.8
2022-03-15 CVE-2022-26994 OS Command Injection vulnerability in Arris products
Arris routers SBR-AC1900P 1.0.7-B05, SBR-AC3200P 1.0.7-B05 and SBR-AC1200P 1.0.5-B05 were discovered to contain a command injection vulnerability in the pptp function via the pptpUserName and pptpPassword parameters.
network
low complexity
arris CWE-78
critical
9.8
2022-03-15 CVE-2022-27003 OS Command Injection vulnerability in Totolink A7000R Firmware and X5000R Firmware
Totolink routers s X5000R V9.1.0u.6118_B20201102 and A7000R V9.1.0u.6115_B20201022 were discovered to contain a command injection vulnerability in the Tunnel 6rd function via the relay6rd parameter.
network
low complexity
totolink CWE-78
critical
9.8
2022-03-15 CVE-2022-27004 OS Command Injection vulnerability in Totolink A7000R Firmware and X5000R Firmware
Totolink routers s X5000R V9.1.0u.6118_B20201102 and A7000R V9.1.0u.6115_B20201022 were discovered to contain a command injection vulnerability in the Tunnel 6in4 function via the remote6in4 parameter.
network
low complexity
totolink CWE-78
critical
9.8
2022-03-15 CVE-2022-27005 OS Command Injection vulnerability in Totolink A7000R Firmware and X5000R Firmware
Totolink routers s X5000R V9.1.0u.6118_B20201102 and A7000R V9.1.0u.6115_B20201022 were discovered to contain a command injection vulnerability in the setWanCfg function via the hostName parameter.
network
low complexity
totolink CWE-78
critical
9.8
2022-03-11 CVE-2022-25621 OS Command Injection vulnerability in NEC products
UUNIVERGE WA 1020 Ver8.2.11 and prior, UNIVERGE WA 1510 Ver8.2.11 and prior, UNIVERGE WA 1511 Ver8.2.11 and prior, UNIVERGE WA 1512 Ver8.2.11 and prior, UNIVERGE WA 2020 Ver8.2.11 and prior, UNIVERGE WA 2021 Ver8.2.11 and prior, UNIVERGE WA 2610-AP Ver8.2.11 and prior, UNIVERGE WA 2611-AP Ver8.2.11 and prior, UNIVERGE WA 2611E-AP Ver8.2.11 and prior, UNIVERGE WA WA2612-AP Ver8.2.11 and prior allows a remote attacker to execute arbitrary OS commands.
network
low complexity
nec CWE-78
critical
9.8