Vulnerabilities > Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

DATE CVE VULNERABILITY TITLE RISK
2018-10-24 CVE-2018-15442 OS Command Injection vulnerability in Cisco Webex Meetings Desktop and Webex Productivity Tools
A vulnerability in the update service of Cisco Webex Meetings Desktop App for Windows could allow an authenticated, local attacker to execute arbitrary commands as a privileged user.
local
low complexity
cisco CWE-78
7.8
2018-10-19 CVE-2018-12670 OS Command Injection vulnerability in Sv3C H.264 POE IP Camera Firmware V2.3.4.2103S50Ntdb20170508B/V2.3.4.2103S50Ntdb20170823B
SV3C L-SERIES HD CAMERA V2.3.4.2103-S50-NTD-B20170508B and V2.3.4.2103-S50-NTD-B20170823B devices allow OS Command Injection.
network
low complexity
sv3c CWE-78
critical
9.8
2018-10-17 CVE-2018-16232 OS Command Injection vulnerability in Ipfire
An authenticated command injection vulnerability exists in IPFire Firewall before 2.21 Core Update 124 in backup.cgi.
network
low complexity
ipfire CWE-78
8.8
2018-10-17 CVE-2018-10823 OS Command Injection vulnerability in Dlink products
An issue was discovered on D-Link DWR-116 through 1.06, DWR-512 through 2.02, DWR-712 through 2.02, DWR-912 through 2.02, DWR-921 through 2.02, and DWR-111 through 1.01 devices.
network
low complexity
dlink CWE-78
8.8
2018-10-17 CVE-2018-3955 OS Command Injection vulnerability in Linksys E1200 Firmware and E2500 Firmware
An exploitable operating system command injection exists in the Linksys ESeries line of routers (Linksys E1200 Firmware Version 2.0.09 and Linksys E2500 Firmware Version 3.0.04).
network
low complexity
linksys CWE-78
7.2
2018-10-17 CVE-2018-3954 OS Command Injection vulnerability in Linksys E1200 Firmware and E2500 Firmware
Devices in the Linksys ESeries line of routers (Linksys E1200 Firmware Version 2.0.09 and Linksys E2500 Firmware Version 3.0.04) are susceptible to OS command injection vulnerabilities due to improper filtering of data passed to and retrieved from NVRAMData entered into the 'Router Name' input field through the web portal is submitted to apply.cgi as the value to the 'machine_name' POST parameter.
network
low complexity
linksys CWE-78
7.2
2018-10-17 CVE-2018-3953 OS Command Injection vulnerability in Linksys E1200 Firmware and E2500 Firmware
Devices in the Linksys ESeries line of routers (Linksys E1200 Firmware Version 2.0.09 and Linksys E2500 Firmware Version 3.0.04) are susceptible to OS command injection vulnerabilities due to improper filtering of data passed to and retrieved from NVRAM.
network
low complexity
linksys CWE-78
7.2
2018-10-16 CVE-2018-14772 OS Command Injection vulnerability in Pydio
Pydio 4.2.1 through 8.2.1 has an authenticated remote code execution vulnerability in which an attacker with administrator access to the web application can execute arbitrary code on the underlying system via Command Injection.
network
low complexity
pydio CWE-78
7.2
2018-10-15 CVE-2018-17532 OS Command Injection vulnerability in Teltonika Rut900 Firmware, Rut950 Firmware and Rut955 Firmware
Teltonika RUT9XX routers with firmware before 00.04.233 are prone to multiple unauthenticated OS command injection vulnerabilities in autologin.cgi and hotspotlogin.cgi due to insufficient user input sanitization.
network
low complexity
teltonika CWE-78
critical
9.8
2018-10-15 CVE-2018-18322 OS Command Injection vulnerability in Control-Webpanel Webpanel 0.9.8.480
CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.480 has Command Injection via shell metacharacters in the admin/index.php service_start, service_restart, service_fullstatus, or service_stop parameter.
network
low complexity
control-webpanel CWE-78
critical
9.8