Vulnerabilities > Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

DATE CVE VULNERABILITY TITLE RISK
2024-11-12 CVE-2024-8881 OS Command Injection vulnerability in Zyxel products
A post-authentication command injection vulnerability in the CGI program in the Zyxel GS1900-48 switch firmware version V2.80(AAHN.1)C0 and earlier could allow an authenticated, LAN-based attacker with administrator privileges to execute some operating system (OS) commands on an affected device by sending a crafted HTTP request.
low complexity
zyxel CWE-78
6.8
2024-11-11 CVE-2024-11062 OS Command Injection vulnerability in Dlink Dsl6740C Firmware
The D-Link DSL6740C modem has an OS Command Injection vulnerability, allowing remote attackers with administrator privileges to inject and execute arbitrary system commands through a specific functionality provided by SSH and Telnet.
network
low complexity
dlink CWE-78
7.2
2024-11-11 CVE-2024-11063 OS Command Injection vulnerability in Dlink Dsl6740C Firmware
The D-Link DSL6740C modem has an OS Command Injection vulnerability, allowing remote attackers with administrator privileges to inject and execute arbitrary system commands through a specific functionality provided by SSH and Telnet.
network
low complexity
dlink CWE-78
7.2
2024-11-11 CVE-2024-11064 OS Command Injection vulnerability in Dlink Dsl6740C Firmware
The D-Link DSL6740C modem has an OS Command Injection vulnerability, allowing remote attackers with administrator privileges to inject and execute arbitrary system commands through a specific functionality provided by SSH and Telnet.
network
low complexity
dlink CWE-78
7.2
2024-11-11 CVE-2024-11065 OS Command Injection vulnerability in Dlink Dsl6740C Firmware
The D-Link DSL6740C modem has an OS Command Injection vulnerability, allowing remote attackers with administrator privileges to inject and execute arbitrary system commands through a specific functionality provided by SSH and Telnet.
network
low complexity
dlink CWE-78
7.2
2024-11-08 CVE-2024-45763 OS Command Injection vulnerability in Dell Enterprise Sonic Distribution
Dell Enterprise SONiC OS, version(s) 4.1.x, 4.2.x, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability.
network
low complexity
dell CWE-78
7.2
2024-11-08 CVE-2024-45765 OS Command Injection vulnerability in Dell Enterprise Sonic Distribution
Dell Enterprise SONiC OS, version(s) 4.1.x, 4.2.x, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability.
network
low complexity
dell CWE-78
7.2
2024-11-06 CVE-2024-10919 OS Command Injection vulnerability in Didi Super-Jacoco 1.0
A vulnerability has been found in didi Super-Jacoco 1.0 and classified as critical.
network
low complexity
didi CWE-78
critical
9.8
2024-11-06 CVE-2024-10915 OS Command Injection vulnerability in Dlink products
A vulnerability was found in D-Link DNS-320, DNS-320LW, DNS-325 and DNS-340L up to 20241028.
network
low complexity
dlink CWE-78
critical
9.8
2024-11-05 CVE-2023-29120 OS Command Injection vulnerability in Enelx Waybox PRO Firmware
Waybox Enel X web management application could be used to execute arbitrary OS commands and provide administrator’s privileges over the Waybox system.
low complexity
enelx CWE-78
8.8