Vulnerabilities > Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

DATE CVE VULNERABILITY TITLE RISK
2025-03-11 CVE-2024-12010 A post-authentication command injection vulnerability in the ”zyUtilMailSend” function of the Zyxel AX7501-B1 firmware version V5.17(ABPC.5.3)C0 and earlier could allow an authenticated attacker with administrator privileges to execute operating system (OS) commands on a vulnerable device.
network
low complexity
CWE-78
7.2
2025-03-07 CVE-2025-2094 OS Command Injection vulnerability in Totolink Ex1800T Firmware 9.1.0Cu.2112B20220316
A vulnerability was found in TOTOLINK EX1800T 9.1.0cu.2112_B20220316.
network
low complexity
totolink CWE-78
critical
9.8
2025-03-07 CVE-2025-2095 OS Command Injection vulnerability in Totolink Ex1800T Firmware 9.1.0Cu.2112B20220316
A vulnerability classified as critical has been found in TOTOLINK EX1800T 9.1.0cu.2112_B20220316.
network
low complexity
totolink CWE-78
critical
9.8
2025-03-07 CVE-2025-2096 OS Command Injection vulnerability in Totolink Ex1800T Firmware 9.1.0Cu.2112B20220316
A vulnerability classified as critical was found in TOTOLINK EX1800T 9.1.0cu.2112_B20220316.
network
low complexity
totolink CWE-78
critical
9.8
2025-03-05 CVE-2025-1316 OS Command Injection vulnerability in Edimax Ic-7100 Firmware
Edimax IC-7100 does not properly neutralize requests.
network
low complexity
edimax CWE-78
critical
9.8
2025-03-02 CVE-2025-1829 OS Command Injection vulnerability in Totolink X18 Firmware 9.1.0Cu.2024B20220329
A vulnerability was found in TOTOLINK X18 9.1.0cu.2024_B20220329.
network
low complexity
totolink CWE-78
8.8
2025-02-26 CVE-2025-20161 A vulnerability in the software upgrade process of Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode could allow an authenticated, local attacker with valid Administrator credentials to execute a command injection attack on the underlying operating system of an affected device. This vulnerability is due to insufficient validation of specific elements within a software image.
local
low complexity
CWE-78
5.1
2025-02-14 CVE-2024-55904 IBM DevOps Deploy 8.0 through 8.0.1.4, 8.1 through 8.1.0.0 / IBM UrbanCode Deploy 7.0 through 7.0.5.25, 7.1 through 7.1.2.21, 7.2 through 7.2.3.14, and 7.3 through 7.3.2.9 could allow a remote privileged authenticated attacker to execute arbitrary commands on the system by sending specially crafted input containing special elements.
network
low complexity
CWE-78
7.2
2025-02-13 CVE-2025-25067 OS Command Injection vulnerability in Myscada Mypro
mySCADA myPRO Manager is vulnerable to an OS command injection which could allow a remote attacker to execute arbitrary OS commands.
network
low complexity
myscada CWE-78
critical
9.8
2025-02-11 CVE-2024-47908 OS Command Injection vulnerability in Ivanti Cloud Services Appliance
OS command injection in the admin web console of Ivanti CSA before version 5.0.5 allows a remote authenticated attacker with admin privileges to achieve remote code execution.
network
low complexity
ivanti CWE-78
7.2