Vulnerabilities > Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

DATE CVE VULNERABILITY TITLE RISK
2018-10-05 CVE-2018-0424 OS Command Injection vulnerability in Cisco Rv110W Firmware, Rv130W Firmware and Rv215W Firmware
A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, Cisco RV130W Wireless-N Multifunction VPN Router, and Cisco RV215W Wireless-N VPN Router could allow an authenticated, remote attacker to execute arbitrary commands.
network
low complexity
cisco CWE-78
8.8
2018-10-02 CVE-2018-17787 OS Command Injection vulnerability in D-Link Dir-823G Firmware
On D-Link DIR-823G devices, the GoAhead configuration allows /HNAP1 Command Injection via shell metacharacters in the POST data, because this data is sent directly to the "system" library function.
network
low complexity
d-link CWE-78
critical
9.8
2018-10-01 CVE-2018-17867 OS Command Injection vulnerability in Dasannetworks H660Gw Firmware
The Port Forwarding functionality on DASAN H660GW devices allows remote attackers to execute arbitrary code via shell metacharacters in the cgi-bin/adv_nat_virsvr.asp Addr parameter (aka the Local IP Address field).
network
low complexity
dasannetworks CWE-78
7.2
2018-09-28 CVE-2018-9077 OS Command Injection vulnerability in Lenovo Lenovoemc Firmware 4.1.402.34662
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, when changing the name of a share, an attacker can craft a command injection payload using backtick "``" characters in the share : name parameter.
network
high complexity
lenovo CWE-78
8.1
2018-09-28 CVE-2018-9076 OS Command Injection vulnerability in Lenovo Lenovoemc Firmware 4.1.402.34662
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, when changing the name of a share, an attacker can craft a command injection payload using backtick "``" characters in the name parameter.
network
high complexity
lenovo CWE-78
8.1
2018-09-28 CVE-2018-9075 OS Command Injection vulnerability in Lenovo Lenovoemc Firmware 4.1.402.34662
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, when joining a PersonalCloud setup, an attacker can craft a command injection payload using backtick "``" characters in the client:password parameter.
network
high complexity
lenovo CWE-78
8.1
2018-09-26 CVE-2018-16055 OS Command Injection vulnerability in Netgate Pfsense
An authenticated command injection vulnerability exists in status_interfaces.php via dhcp_relinquish_lease() in pfSense before 2.4.4 due to its passing user input from the $_POST parameters "ifdescr" and "ipv" to a shell without escaping the contents of the variables.
network
low complexity
netgate CWE-78
8.8
2018-09-21 CVE-2018-17317 OS Command Injection vulnerability in Fruitywifi Project Fruitywifi 2.1
FruityWifi (aka PatatasFritas/PatataWifi) 2.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the io_mode, ap_mode, io_action, io_in_iface, io_in_set, io_in_ip, io_in_mask, io_in_gw, io_out_iface, io_out_set, io_out_mask, io_out_gw, iface, or domain parameter to /www/script/config_iface.php, or the newSSID, hostapd_secure, hostapd_wpa_passphrase, or supplicant_ssid parameter to /www/page_config.php.
network
low complexity
fruitywifi-project CWE-78
critical
9.8
2018-09-20 CVE-2018-16282 OS Command Injection vulnerability in Moxa Edr-810 Firmware 4.2
A command injection vulnerability in the web server functionality of Moxa EDR-810 V4.2 build 18041013 allows remote attackers to execute arbitrary OS commands with root privilege via the caname parameter to the /xml/net_WebCADELETEGetValue URI.
network
low complexity
moxa CWE-78
8.8
2018-09-19 CVE-2018-17228 OS Command Injection vulnerability in Nmap4J Project Nmap4J 1.1.0
nmap4j 1.1.0 allows attackers to execute arbitrary commands via shell metacharacters in an includeHosts call.
network
low complexity
nmap4j-project CWE-78
critical
9.8