Vulnerabilities > Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

DATE CVE VULNERABILITY TITLE RISK
2020-10-08 CVE-2020-3602 OS Command Injection vulnerability in Cisco Staros
A vulnerability in the CLI of Cisco StarOS operating system for Cisco ASR 5000 Series Routers could allow an authenticated, local attacker to elevate privileges on an affected device.
local
low complexity
cisco CWE-78
6.7
2020-10-08 CVE-2020-3601 OS Command Injection vulnerability in Cisco Staros
A vulnerability in the CLI of Cisco StarOS operating system for Cisco ASR 5000 Series Routers could allow an authenticated, local attacker to elevate privileges on an affected device.
local
low complexity
cisco CWE-78
6.7
2020-10-06 CVE-2020-26582 OS Command Injection vulnerability in Dlink Dap-1360U Firmware
D-Link DAP-1360U before 3.0.1 devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the IP JSON value for ping (aka res_config_action=3&res_config_id=18).
network
low complexity
dlink CWE-78
8.8
2020-10-02 CVE-2020-14293 OS Command Injection vulnerability in Secudos Domos 5.6/5.6.1/5.8
conf_datetime in Secudos DOMOS 5.8 allows remote attackers to execute arbitrary commands as root via shell metacharacters in the zone field (obtained from the web interface).
network
high complexity
secudos CWE-78
7.5
2020-10-02 CVE-2020-12124 OS Command Injection vulnerability in Wavlink Wn530H4 Firmware M30H4.V5030.190403
A remote command-line injection vulnerability in the /cgi-bin/live_api.cgi endpoint of the WAVLINK WN530H4 M30H4.V5030.190403 allows an attacker to execute arbitrary Linux commands as root without authentication.
network
low complexity
wavlink CWE-78
critical
9.8
2020-09-25 CVE-2020-25223 OS Command Injection vulnerability in Sophos Unified Threat Management
A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM before v9.705 MR5, v9.607 MR7, and v9.511 MR11
network
low complexity
sophos CWE-78
critical
9.8
2020-09-24 CVE-2020-3417 OS Command Injection vulnerability in Cisco IOS XE
A vulnerability in Cisco IOS XE Software could allow an authenticated, local attacker to execute persistent code at boot time and break the chain of trust.
local
low complexity
cisco CWE-78
6.7
2020-09-24 CVE-2020-3403 OS Command Injection vulnerability in Cisco IOS XE 17.2.1
A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker to inject a command to the underlying operating system that will execute with root privileges upon the next reboot of the device.
local
low complexity
cisco CWE-78
7.8
2020-09-24 CVE-2020-16148 OS Command Injection vulnerability in Telmat products
The ping page of the administration panel in Telmat AccessLog <= 6.0 (TAL_20180415) allows an attacker to get root shell access via authenticated code injection over the network.
network
low complexity
telmat CWE-78
7.2
2020-09-24 CVE-2020-16147 OS Command Injection vulnerability in Telmat products
The login page in Telmat AccessLog <= 6.0 (TAL_20180415) allows an attacker to get root shell access via Unauthenticated code injection over the network.
network
low complexity
telmat CWE-78
critical
9.8