Vulnerabilities > Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

DATE CVE VULNERABILITY TITLE RISK
2023-11-30 CVE-2023-48810 OS Command Injection vulnerability in Totolink X6000R Firmware 9.4.0Cu.852B20230719
In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function when passed to the CsteSystem function creates a command execution vulnerability.
network
low complexity
totolink CWE-78
critical
9.8
2023-11-30 CVE-2023-48811 OS Command Injection vulnerability in Totolink X6000R Firmware 9.4.0Cu.852B20230719
In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function that when passed to the CsteSystem function creates a command execution vulnerability.
network
low complexity
totolink CWE-78
critical
9.8
2023-11-30 CVE-2023-48812 OS Command Injection vulnerability in Totolink X6000R Firmware 9.4.0Cu.852B20230719
In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function that when passed to the CsteSystem function creates a command execution vulnerability.
network
low complexity
totolink CWE-78
critical
9.8
2023-11-30 CVE-2023-3741 OS Command Injection vulnerability in NEC products
An OS Command injection vulnerability in NEC Platforms DT900 and DT900S Series all versions allows an attacker to execute any command on the device.
network
low complexity
nec CWE-78
critical
9.8
2023-11-29 CVE-2023-23325 OS Command Injection vulnerability in Zumtobel Netlink CCD Firmware 3.80
Zumtobel Netlink CCD Onboard 3.74 - Firmware 3.80 was discovered to contain a command injection vulnerability via the NetHostname parameter.
network
low complexity
zumtobel CWE-78
critical
9.8
2023-11-28 CVE-2023-4221 OS Command Injection vulnerability in Chamilo LMS
Command injection in `main/lp/openoffice_presentation.class.php` in Chamilo LMS <= v1.11.24 allows users permitted to upload Learning Paths to obtain remote code execution via improper neutralisation of special characters.
network
low complexity
chamilo CWE-78
8.8
2023-11-28 CVE-2023-4222 OS Command Injection vulnerability in Chamilo LMS
Command injection in `main/lp/openoffice_text_document.class.php` in Chamilo LMS <= v1.11.24 allows users permitted to upload Learning Paths to obtain remote code execution via improper neutralisation of special characters.
network
low complexity
chamilo CWE-78
8.8
2023-11-28 CVE-2023-3368 OS Command Injection vulnerability in Chamilo
Command injection in `/main/webservices/additional_webservices.php` in Chamilo LMS <= v1.11.20 allows unauthenticated attackers to obtain remote code execution via improper neutralisation of special characters.
network
low complexity
chamilo CWE-78
critical
9.8
2023-11-27 CVE-2023-6304 OS Command Injection vulnerability in Tecno-Mobile Tr118 Firmware Tr118M30Errdenfrarswhapoopv00820220830
A vulnerability was found in Tecno 4G Portable WiFi TR118 TR118-M30E-RR-D-EnFrArSwHaPo-OP-V008-20220830.
low complexity
tecno-mobile CWE-78
8.0
2023-11-20 CVE-2023-35762 OS Command Injection vulnerability in Inea ME RTU Firmware 3.36/3.36B
Versions of INEA ME RTU firmware 3.36b and prior are vulnerable to operating system (OS) command injection, which could allow remote code execution.
network
low complexity
inea CWE-78
critical
9.8