Vulnerabilities > Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

DATE CVE VULNERABILITY TITLE RISK
2023-12-13 CVE-2023-6792 OS Command Injection vulnerability in Paloaltonetworks Pan-Os
An OS command injection vulnerability in the XML API of Palo Alto Networks PAN-OS software enables an authenticated API user to disrupt system processes and potentially execute arbitrary code with limited privileges on the firewall.
network
low complexity
paloaltonetworks CWE-78
6.3
2023-12-13 CVE-2023-6795 OS Command Injection vulnerability in Paloaltonetworks Pan-Os
An OS command injection vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to disrupt system processes and potentially execute arbitrary code with limited privileges on the firewall.
network
low complexity
paloaltonetworks CWE-78
4.7
2023-12-12 CVE-2023-46454 OS Command Injection vulnerability in Gl-Inet Gl-Ar300M Firmware 4.3.7
In GL.iNET GL-AR300M routers with firmware v4.3.7, it is possible to inject arbitrary shell commands through a crafted package name in the package information functionality.
network
low complexity
gl-inet CWE-78
critical
9.8
2023-12-12 CVE-2023-49695 OS Command Injection vulnerability in Elecom products
OS command injection vulnerability in WRC-X3000GSN v1.0.2, WRC-X3000GS v1.0.24 and earlier, and WRC-X3000GSA v1.0.24 and earlier allows a network-adjacent attacker with an administrative privilege to execute an arbitrary OS command by sending a specially crafted request to the product.
low complexity
elecom CWE-78
6.8
2023-12-12 CVE-2022-48616 OS Command Injection vulnerability in Huawei Ar617Vw Firmware V300R21C00Spc200
A Huawei data communication product has a command injection vulnerability.
network
high complexity
huawei CWE-78
7.5
2023-12-09 CVE-2023-47254 OS Command Injection vulnerability in Draytek Vigor167 Firmware 5.2.2
An OS Command Injection in the CLI interface on DrayTek Vigor167 version 5.2.2, allows remote attackers to execute arbitrary system commands and escalate privileges via any account created within the web interface.
network
low complexity
draytek CWE-78
critical
9.8
2023-12-08 CVE-2023-46157 OS Command Injection vulnerability in Mgt-Commerce Cloudpanel
File-Manager in MGT CloudPanel 2.0.0 through 2.3.2 allows the lowest privilege user to achieve OS command injection by changing file ownership and changing file permissions to 4755.
network
low complexity
mgt-commerce CWE-78
8.8
2023-12-08 CVE-2023-43744 OS Command Injection vulnerability in Zultys products
An OS command injection vulnerability in Zultys MX-SE, MX-SE II, MX-E, MX-Virtual, MX250, and MX30 with firmware versions prior to 17.0.10 patch 17161 and 16.04 patch 16109 allows an administrator to execute arbitrary OS commands via a file name parameter in a patch application function.
network
low complexity
zultys CWE-78
7.2
2023-12-06 CVE-2023-49897 OS Command Injection vulnerability in FXC Ae1021 Firmware and Ae1021Pe Firmware
An OS command injection vulnerability exists in AE1021PE firmware version 2.0.9 and earlier and AE1021 firmware version 2.0.9 and earlier.
network
low complexity
fxc CWE-78
8.8
2023-12-05 CVE-2023-44221 OS Command Injection vulnerability in Sonicwall products
Improper neutralization of special elements in the SMA100 SSL-VPN management interface allows a remote authenticated attacker with administrative privilege to inject arbitrary commands as a 'nobody' user, potentially leading to OS Command Injection Vulnerability.
network
low complexity
sonicwall CWE-78
7.2