Vulnerabilities > Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

DATE CVE VULNERABILITY TITLE RISK
2023-12-08 CVE-2023-46157 OS Command Injection vulnerability in Mgt-Commerce Cloudpanel
File-Manager in MGT CloudPanel 2.0.0 through 2.3.2 allows the lowest privilege user to achieve OS command injection by changing file ownership and changing file permissions to 4755.
network
low complexity
mgt-commerce CWE-78
8.8
2023-12-08 CVE-2023-43744 OS Command Injection vulnerability in Zultys products
An OS command injection vulnerability in Zultys MX-SE, MX-SE II, MX-E, MX-Virtual, MX250, and MX30 with firmware versions prior to 17.0.10 patch 17161 and 16.04 patch 16109 allows an administrator to execute arbitrary OS commands via a file name parameter in a patch application function.
network
low complexity
zultys CWE-78
7.2
2023-12-06 CVE-2023-49897 OS Command Injection vulnerability in FXC Ae1021 Firmware and Ae1021Pe Firmware
An OS command injection vulnerability exists in AE1021PE firmware version 2.0.9 and earlier and AE1021 firmware version 2.0.9 and earlier.
network
low complexity
fxc CWE-78
8.8
2023-12-05 CVE-2023-44221 OS Command Injection vulnerability in Sonicwall products
Improper neutralization of special elements in the SMA100 SSL-VPN management interface allows a remote authenticated attacker with administrative privilege to inject arbitrary commands as a 'nobody' user, potentially leading to OS Command Injection Vulnerability.
network
low complexity
sonicwall CWE-78
7.2
2023-12-05 CVE-2023-6357 OS Command Injection vulnerability in Codesys products
A low-privileged remote attacker could exploit the vulnerability and inject additional system commands via file system libraries which could give the attacker full control of the device.
network
low complexity
codesys CWE-78
8.8
2023-12-04 CVE-2023-48800 OS Command Injection vulnerability in Totolink X6000R Firmware 9.4.0Cu.852B20230719
In TOTOLINK X6000R_Firmware V9.4.0cu.852_B20230719, the shttpd file sub_417338 function obtains fields from the front-end, connects them through the snprintf function, and passes them to the CsteSystem function, resulting in a command execution vulnerability.
network
low complexity
totolink CWE-78
critical
9.8
2023-12-04 CVE-2023-44291 OS Command Injection vulnerability in Dell Powerprotect Data Manager Dm5500 Firmware
Dell DM5500 5.14.0.0 contains an OS command injection vulnerability in the appliance.
network
low complexity
dell CWE-78
7.2
2023-12-04 CVE-2023-44304 OS Command Injection vulnerability in Dell Dm5500 Firmware 5.14.0.0
Dell DM5500 contains a privilege escalation vulnerability in the appliance.
network
low complexity
dell CWE-78
8.8
2023-11-30 CVE-2023-48802 OS Command Injection vulnerability in Totolink X6000R Firmware 9.4.0Cu.852B20230719
In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function when passed to the CsteSystem function creates a command execution vulnerability.
network
low complexity
totolink CWE-78
critical
9.8
2023-11-30 CVE-2023-48803 OS Command Injection vulnerability in Totolink X6000R Firmware 9.4.0Cu.852B20230719
In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function when passed to the CsteSystem function creates a command execution vulnerability.
network
low complexity
totolink CWE-78
critical
9.8