Vulnerabilities > Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

DATE CVE VULNERABILITY TITLE RISK
2020-12-30 CVE-2020-35789 OS Command Injection vulnerability in Netgear Nms300 Firmware
NETGEAR NMS300 devices before 1.6.0.27 are affected by command injection by an authenticated user.
network
low complexity
netgear CWE-78
8.8
2020-12-30 CVE-2020-10209 OS Command Injection vulnerability in Amino products
Command Injection in the CPE WAN Management Protocol (CWMP) registration in Amino Communications AK45x series, AK5xx series, AK65x series, Aria6xx series, Aria7/AK7Xx series and Kami7B allows man-in-the-middle attackers to execute arbitrary commands with root level privileges.
network
high complexity
amino CWE-78
8.1
2020-12-27 CVE-2020-35729 OS Command Injection vulnerability in Klogserver Klog Server 2.4.1
KLog Server 2.4.1 allows OS command injection via shell metacharacters in the actions/authenticate.php user parameter.
network
low complexity
klogserver CWE-78
critical
9.8
2020-12-26 CVE-2020-35715 OS Command Injection vulnerability in Linksys Re6500 Firmware
Belkin LINKSYS RE6500 devices before 1.0.012.001 allow remote authenticated users to execute arbitrary commands via shell metacharacters in a filename to the upload_settings.cgi page.
network
low complexity
linksys CWE-78
8.8
2020-12-26 CVE-2020-35714 OS Command Injection vulnerability in Linksys Re6500 Firmware
Belkin LINKSYS RE6500 devices before 1.0.11.001 allow remote authenticated users to execute arbitrary commands via goform/systemCommand?command= in conjunction with the goform/pingstart program.
network
low complexity
linksys CWE-78
8.8
2020-12-26 CVE-2020-35713 OS Command Injection vulnerability in Linksys Re6500 Firmware
Belkin LINKSYS RE6500 devices before 1.0.012.001 allow remote attackers to execute arbitrary commands or set a new password via shell metacharacters to the goform/setSysAdm page.
network
low complexity
linksys CWE-78
critical
9.8
2020-12-24 CVE-2020-28188 OS Command Injection vulnerability in Terra-Master TOS
Remote Command Execution (RCE) vulnerability in TerraMaster TOS <= 4.2.06 allow remote unauthenticated attackers to inject OS commands via /include/makecvs.php in Event parameter.
network
low complexity
terra-master CWE-78
critical
9.8
2020-12-23 CVE-2020-35665 OS Command Injection vulnerability in Terra-Master Terramaster Operating System 3.0.33/3.1.03/4.2.06
An unauthenticated command-execution vulnerability exists in TerraMaster TOS through 4.2.06 via shell metacharacters in the Event parameter in include/makecvs.php during CSV creation.
network
low complexity
terra-master CWE-78
critical
9.8
2020-12-23 CVE-2020-29552 OS Command Injection vulnerability in Urve 24.03.2020
An issue was discovered in URVE Build 24.03.2020.
network
low complexity
urve CWE-78
critical
9.8
2020-12-22 CVE-2020-24581 OS Command Injection vulnerability in Dlink Dsl2888A Firmware
An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55.
low complexity
dlink CWE-78
8.0