Vulnerabilities > Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

DATE CVE VULNERABILITY TITLE RISK
2023-04-22 CVE-2023-25507 OS Command Injection vulnerability in Nvidia BMC
NVIDIA DGX-1 BMC contains a vulnerability in the SPX REST API, where an attacker with the appropriate level of authorization can inject arbitrary shell commands, which may lead to code execution, denial of service, information disclosure, and data tampering.
network
low complexity
nvidia CWE-78
8.8
2023-04-20 CVE-2023-2131 OS Command Injection vulnerability in Inea ME RTU Firmware
Versions of INEA ME RTU firmware prior to 3.36 are vulnerable to OS command injection, which could allow an attacker to remotely execute arbitrary code.
network
low complexity
inea CWE-78
critical
9.8
2023-04-19 CVE-2023-25759 OS Command Injection vulnerability in Uniguest Tripleplay 3.4.0
OS Command Injection in TripleData Reporting Engine in Tripleplay Platform releases prior to Caveman 3.4.0 allows authenticated users to run unprivileged OS level commands via a crafted request payload.
network
low complexity
uniguest CWE-78
5.4
2023-04-16 CVE-2022-38841 OS Command Injection vulnerability in Linksys E8450 Firmware 1.1.00
Linksys AX3200 1.1.00 is vulnerable to OS command injection by authenticated users via shell metacharacters to the diagnostics traceroute page.
network
low complexity
linksys CWE-78
8.8
2023-04-14 CVE-2023-29804 OS Command Injection vulnerability in Iodata Wfs-Sr03K Firmware and Wfs-Sr03W Firmware
WFS-SR03 v1.0.3 was discovered to contain a command injection vulnerability via the sys_smb_pwdmod function.
network
low complexity
iodata CWE-78
8.8
2023-04-14 CVE-2023-29805 OS Command Injection vulnerability in Iodata Wfs-Sr03K Firmware and Wfs-Sr03W Firmware
WFS-SR03 v1.0.3 was discovered to contain a command injection vulnerability via the pro_stor_canceltrans_handler_part_19 function.
network
low complexity
iodata CWE-78
critical
9.8
2023-04-12 CVE-2023-27216 OS Command Injection vulnerability in Dlink Dsl-3782 Firmware 1.03
An issue found in D-Link DSL-3782 v.1.03 allows remote authenticated users to execute arbitrary code as root via the network settings page.
network
low complexity
dlink CWE-78
8.8
2023-04-12 CVE-2023-27826 OS Command Injection vulnerability in Seowonintech Swc-5100W Firmware 1.11.0.1/1.9.9.4
SeowonIntech SWC 5100W WIMAX Bootloader 1.18.19.0, HW 0.0.7.0, and FW 1.11.0.1, 1.9.9.4 are vulnerable to OS Command Injection.
network
low complexity
seowonintech CWE-78
8.8
2023-04-11 CVE-2022-40679 OS Command Injection vulnerability in Fortinet Fortiadc, Fortiddos and Fortiddos-F
An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in FortiADC 5.x all versions, 6.0 all versions, 6.1 all versions, 6.2.0 through 6.2.4, 7.0.0 through 7.0.3, 7.1.0; FortiDDoS 4.x all versions, 5.0 all versions, 5.1 all versions, 5.2 all versions, 5.3 all versions, 5.4 all versions, 5.5 all versions, 5.6 all versions and FortiDDoS-F 6.4.0, 6.3.0 through 6.3.3, 6.2.0 through 6.2.2, 6.1.0 through 6.1.4 may allow an authenticated attacker to execute unauthorized commands via specifically crafted arguments to existing commands.
local
low complexity
fortinet CWE-78
7.8
2023-04-11 CVE-2022-43948 OS Command Injection vulnerability in Fortinet Fortiadc and Fortiweb
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb version 7.0.0 through 7.0.3, FortiADC version 7.1.0 through 7.1.1, FortiADC version 7.0.0 through 7.0.3, FortiADC 6.2 all versions, FortiADC 6.1 all versions, FortiADC 6.0 all versions, FortiADC 5.4 all versions, FortiADC 5.3 all versions, FortiADC 5.2 all versions, FortiADC 5.1 all versions allows attacker to execute unauthorized code or commands via specifically crafted arguments to existing commands.
local
low complexity
fortinet CWE-78
7.8