Vulnerabilities > Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

DATE CVE VULNERABILITY TITLE RISK
2024-09-04 CVE-2024-43405 OS Command Injection vulnerability in Projectdiscovery Nuclei
Nuclei is a vulnerability scanner powered by YAML based templates.
local
low complexity
projectdiscovery CWE-78
7.8
2024-09-03 CVE-2024-7261 OS Command Injection vulnerability in Zyxel products
The improper neutralization of special elements in the parameter "host" in the CGI program of Zyxel NWA1123ACv3 firmware version 6.70(ABVT.4) and earlier, WAC500 firmware version 6.70(ABVS.4) and earlier, WAX655E firmware version 7.00(ACDO.1) and earlier, WBE530 firmware version 7.00(ACLE.1) and earlier, and USG LITE 60AX firmware version V2.00(ACIP.2) could allow an unauthenticated attacker to execute OS commands by sending a crafted cookie to a vulnerable device.
network
low complexity
zyxel CWE-78
critical
9.8
2024-09-03 CVE-2024-42057 OS Command Injection vulnerability in Zyxel ZLD
A command injection vulnerability in the IPSec VPN feature of Zyxel ATP series firmware versions from V4.32 through V5.38, USG FLEX series firmware versions from V4.50 through V5.38, USG FLEX 50(W) series firmware versions from V4.16 through V5.38, and USG20(W)-VPN series firmware versions from V4.16 through V5.38 could allow an unauthenticated attacker to execute some OS commands on an affected device by sending a crafted username to the vulnerable device.
network
high complexity
zyxel CWE-78
8.1
2024-09-03 CVE-2024-42059 OS Command Injection vulnerability in Zyxel ZLD
A post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V5.00 through V5.38, USG FLEX series firmware versions from V5.00 through V5.38, USG FLEX 50(W) series firmware versions from V5.00 through V5.38, and USG20(W)-VPN series firmware versions from V5.00 through V5.38 could allow an authenticated attacker with administrator privileges to execute some OS commands on an affected device by uploading a crafted compressed language file via FTP.
network
low complexity
zyxel CWE-78
7.2
2024-09-03 CVE-2024-42060 OS Command Injection vulnerability in Zyxel ZLD
A post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V4.32 through V5.38, USG FLEX series firmware versions from V4.50 through V5.38, USG FLEX 50(W) series firmware versions from V4.16 through V5.38, and USG20(W)-VPN series firmware versions from V4.16 through V5.38 could allow an authenticated attacker with administrator privileges to execute some OS commands on an affected device by uploading a crafted internal user agreement file to the vulnerable device.
network
low complexity
zyxel CWE-78
7.2
2024-09-03 CVE-2024-7203 OS Command Injection vulnerability in Zyxel ZLD
A post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V4.60 through V5.38 and USG FLEX series firmware versions from V4.60 through V5.38 could allow an authenticated attacker with administrator privileges to execute some operating system (OS) commands on an affected device by executing a crafted CLI command.
network
low complexity
zyxel CWE-78
7.2
2024-08-29 CVE-2024-43804 OS Command Injection vulnerability in Roxy-Wi 8.0
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers.
network
low complexity
roxy-wi CWE-78
8.8
2024-08-27 CVE-2024-8213 OS Command Injection vulnerability in Dlink products
A vulnerability classified as critical has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20240814.
network
low complexity
dlink CWE-78
critical
9.8
2024-08-27 CVE-2024-8214 OS Command Injection vulnerability in Dlink products
A vulnerability classified as critical was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20240814.
network
low complexity
dlink CWE-78
critical
9.8
2024-08-27 CVE-2024-8210 OS Command Injection vulnerability in Dlink products
A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20240814.
network
low complexity
dlink CWE-78
critical
9.8