Vulnerabilities > Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

DATE CVE VULNERABILITY TITLE RISK
2018-07-17 CVE-2018-0708 OS Command Injection vulnerability in Qnap Q'Center
Command injection vulnerability in networking of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authenticated users to run arbitrary commands.
network
low complexity
qnap CWE-78
8.8
2018-07-17 CVE-2018-0707 OS Command Injection vulnerability in Qnap Q'Center
Command injection vulnerability in change password of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authenticated users to run arbitrary commands.
network
low complexity
qnap CWE-78
7.2
2018-07-16 CVE-2018-0341 OS Command Injection vulnerability in Cisco IP Phone Multiplatform Firmware 11.1(2)
A vulnerability in the web-based UI of Cisco IP Phone 6800, 7800, and 8800 Series with Multiplatform Firmware before 11.2(1) could allow an authenticated, remote attacker to perform a command injection and execute commands with the privileges of the web server.
network
low complexity
cisco CWE-78
8.8
2018-07-15 CVE-2018-14060 OS Command Injection vulnerability in MI Xiaomi R3D Firmware
OS command injection in the AP mode settings feature in /cgi-bin/luci /api/misystem/set_router_wifiap on Xiaomi R3D before 2.26.4 devices allows an attacker to execute any command via crafted JSON data.
network
low complexity
mi CWE-78
critical
9.8
2018-07-15 CVE-2018-14010 OS Command Injection vulnerability in MI products
OS command injection in the guest Wi-Fi settings feature in /cgi-bin/luci on Xiaomi R3P before 2.14.5, R3C before 2.12.15, R3 before 2.22.15, and R3D before 2.26.4 devices allows an attacker to execute any command via crafted JSON data.
network
low complexity
mi CWE-78
critical
9.8
2018-07-10 CVE-2018-5553 OS Command Injection vulnerability in Crestron products
The Crestron Console service running on DGE-100, DM-DGE-200-C, and TS-1542-C devices with default configuration and running firmware versions 1.3384.00049.001 and lower are vulnerable to command injection that can be used to gain root-level access.
network
low complexity
crestron CWE-78
critical
9.8
2018-07-10 CVE-2018-13797 OS Command Injection vulnerability in Node-Macaddress Project Node-Macaddress
The macaddress module before 0.2.9 for Node.js is prone to an arbitrary command injection flaw, due to allowing unsanitized input to an exec (rather than execFile) call.
network
low complexity
node-macaddress-project CWE-78
critical
9.8
2018-07-09 CVE-2018-6831 OS Command Injection vulnerability in Foscam products
The setSystemTime function in Foscam Cameras C1 Lite V3, and C1 V3 with firmware 2.82.2.33 and earlier, FI9800P V3, FI9803P V4, FI9851P V3, and FI9853EP V2 2.84.2.33 and earlier, FI9816P V3, FI9821EP V2, FI9821P V3, FI9826P V3, and FI9831P V3 2.81.2.33 and earlier, C1, C1 V2, C1 Lite, and C1 Lite V2 2.52.2.47 and earlier, FI9800P, FI9800P V2, FI9803P V2, FI9803P V3, and FI9851P V2 2.54.2.47 and earlier, FI9815P, FI9815P V2, FI9816P, and FI9816P V2, 2.51.2.47 and earlier, R2 and R4 2.71.1.59 and earlier, C2 and FI9961EP 2.72.1.59 and earlier, FI9900EP, FI9900P, and FI9901EP 2.74.1.59 and earlier, FI9928P 2.74.1.58 and earlier, FI9803EP and FI9853EP 2.22.2.31 and earlier, FI9803P and FI9851P 2.24.2.31 and earlier, FI9821P V2, FI9826P V2, FI9831P V2, and FI9821EP 2.21.2.31 and earlier, FI9821W V2, FI9831W, FI9826W, FI9821P, FI9831P, and FI9826P 2.11.1.120 and earlier, FI9818W V2 2.13.2.120 and earlier, FI9805W, FI9804W, FI9804P, FI9805E, and FI9805P 2.14.1.120 and earlier, FI9828P, and FI9828W 2.13.1.120 and earlier, and FI9828P V2 2.11.1.133 and earlier allows remote authenticated users to execute arbitrary commands via a ';' in the ntpServer argument.
network
low complexity
foscam CWE-78
7.2
2018-07-05 CVE-2018-10987 OS Command Injection vulnerability in Diqee Diqee360 Firmware
An issue was discovered on Dongguan Diqee Diqee360 devices.
network
high complexity
diqee CWE-78
7.5
2018-07-02 CVE-2018-9276 OS Command Injection vulnerability in Paessler Prtg Network Monitor
An issue was discovered in PRTG Network Monitor before 18.2.39.
network
low complexity
paessler CWE-78
7.2