Vulnerabilities > Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

DATE CVE VULNERABILITY TITLE RISK
2022-02-10 CVE-2022-20708 OS Command Injection vulnerability in Cisco products
Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization protections Fetch and run unsigned software Cause denial of service (DoS) For more information about these vulnerabilities, see the Details section of this advisory.
low complexity
cisco CWE-78
8.0
2022-02-09 CVE-2021-26616 OS Command Injection vulnerability in Secuwiz Secuwayssl U 2.0.0.4/2.0.0.8
An OS command injection was found in SecuwaySSL, when special characters injection on execute command with runCommand arguments.
network
low complexity
secuwiz CWE-78
critical
9.8
2022-02-06 CVE-2022-24552 OS Command Injection vulnerability in Starwindsoftware NAS and SAN
A flaw was found in the REST API in StarWind Stack.
network
low complexity
starwindsoftware CWE-78
critical
9.8
2022-02-04 CVE-2022-0365 OS Command Injection vulnerability in Riconmobile S9922L Firmware and S9922Xl Firmware
The affected product is vulnerable to an authenticated OS command injection, which may allow an attacker to inject and execute arbitrary shell commands as the Admin (root) user.
network
low complexity
riconmobile CWE-78
critical
9.8
2022-02-04 CVE-2022-23611 OS Command Injection vulnerability in Itunesrpc-Remastered Project Itunesrpc-Remastered
iTunesRPC-Remastered is a Discord Rich Presence for iTunes on Windows utility.
network
low complexity
itunesrpc-remastered-project CWE-78
critical
9.8
2022-02-04 CVE-2021-29393 OS Command Injection vulnerability in Globalnorthstar Northstar Club Management 6.3
Remote Code Execution in cominput.jsp and comoutput.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote unauthenticated users to inject and execute arbitrary system commands via the unsanitized user-controlled "command" and "commandvalues" parameters.
network
low complexity
globalnorthstar CWE-78
critical
9.8
2022-02-04 CVE-2021-45986 OS Command Injection vulnerability in Tendacn G1 Firmware and G3 Firmware
Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function formSetUSBShareInfo.
network
low complexity
tendacn CWE-78
critical
9.8
2022-02-04 CVE-2021-45987 OS Command Injection vulnerability in Tendacn G1 Firmware and G3 Firmware
Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function formSetNetCheckTools.
network
low complexity
tendacn CWE-78
critical
9.8
2022-02-02 CVE-2021-41018 OS Command Injection vulnerability in Fortinet Fortiweb
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below allows attacker to execute unauthorized code or commands via crafted HTTP requests.
network
low complexity
fortinet CWE-78
8.8
2022-02-02 CVE-2021-41016 OS Command Injection vulnerability in Fortinet Fortiextender Firmware
A improper neutralization of special elements used in a command ('command injection') in Fortinet FortiExtender version 7.0.1 and below, 4.2.3 and below, 4.1.7 and below allows an authenticated attacker to execute privileged shell commands via CLI commands including special characters
network
low complexity
fortinet CWE-78
8.8