Vulnerabilities > Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

DATE CVE VULNERABILITY TITLE RISK
2019-05-10 CVE-2018-7082 OS Command Injection vulnerability in multiple products
A command injection vulnerability is present in Aruba Instant that permits an authenticated administrative user to execute arbitrary commands on the underlying operating system.
network
low complexity
arubanetworks siemens CWE-78
7.2
2019-05-09 CVE-2019-11353 OS Command Injection vulnerability in Engeniustech Ews660Ap Firmware 2.0.284
The EnGenius EWS660AP router with firmware 2.0.284 allows an attacker to execute arbitrary commands using the built-in ping and traceroute utilities by using different payloads and injecting multiple parameters.
network
low complexity
engeniustech CWE-78
critical
9.8
2019-05-06 CVE-2018-4061 OS Command Injection vulnerability in Sierrawireless Airlink Es450 Firmware 4.9.3
An exploitable command injection vulnerability exists in the ACEManager iplogging.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3.
network
low complexity
sierrawireless CWE-78
8.8
2019-05-03 CVE-2019-1709 OS Command Injection vulnerability in Cisco products
A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to perform a command injection attack.
local
low complexity
cisco CWE-78
7.8
2019-05-03 CVE-2019-1699 OS Command Injection vulnerability in Cisco Secure Firewall Management Center
A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to perform a command injection attack.
local
low complexity
cisco CWE-78
7.8
2019-05-02 CVE-2017-18372 OS Command Injection vulnerability in multiple products
The Billion 5200W-T TCLinux Fw $7.3.8.0 v008 130603 router distributed by TrueOnline has a command injection vulnerability in the Time Setting function, which is only accessible by an authenticated user.
network
low complexity
billion zyxel CWE-78
8.8
2019-05-02 CVE-2017-18370 OS Command Injection vulnerability in multiple products
The ZyXEL P660HN-T1A v2 TCLinux Fw #7.3.37.6 router distributed by TrueOnline has a command injection vulnerability in the Remote System Log forwarding function, which is only accessible by an authenticated user.
network
low complexity
billion zyxel CWE-78
8.8
2019-05-02 CVE-2017-18369 OS Command Injection vulnerability in Billion 5200W-T Firmware 1.02B
The Billion 5200W-T 1.02b.rc5.dt49 router distributed by TrueOnline has a command injection vulnerability in the Remote System Log forwarding function, which is accessible by an unauthenticated user.
network
low complexity
billion CWE-78
critical
9.8
2019-05-02 CVE-2017-18368 OS Command Injection vulnerability in multiple products
The ZyXEL P660HN-T1A v1 TCLinux Fw $7.3.15.0 v001 / 3.40(ULM.0)b31 router distributed by TrueOnline has a command injection vulnerability in the Remote System Log forwarding function, which is accessible by an unauthenticated user.
network
low complexity
billion zyxel CWE-78
critical
9.8
2019-04-30 CVE-2019-11627 OS Command Injection vulnerability in multiple products
gpg-key2ps in signing-party 1.1.x and 2.x before 2.10-1 contains an unsafe shell call enabling shell injection via a User ID.
network
low complexity
signing-party-project debian opensuse CWE-78
critical
9.8