Vulnerabilities > Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

DATE CVE VULNERABILITY TITLE RISK
2023-01-17 CVE-2022-47853 OS Command Injection vulnerability in Totolink A7100Ru Firmware 7.4Cu.2313B20191024
TOTOlink A7100RU V7.4cu.2313_B20191024 is vulnerable to Command Injection Vulnerability in the httpd service.
network
low complexity
totolink CWE-78
critical
9.8
2023-01-17 CVE-2023-22279 OS Command Injection vulnerability in Ate-Mahoroba products
MAHO-PBX NetDevancer Lite/Uni/Pro/Cloud prior to Ver.1.11.00, MAHO-PBX NetDevancer VSG Lite/Uni prior to Ver.1.11.00, and MAHO-PBX NetDevancer MobileGate Home/Office prior to Ver.1.11.00 allow a remote unauthenticated attacker to execute an arbitrary OS command.
network
low complexity
ate-mahoroba CWE-78
critical
9.8
2023-01-17 CVE-2023-22280 OS Command Injection vulnerability in Ate-Mahoroba products
MAHO-PBX NetDevancer Lite/Uni/Pro/Cloud prior to Ver.1.11.00, MAHO-PBX NetDevancer VSG Lite/Uni prior to Ver.1.11.00, and MAHO-PBX NetDevancer MobileGate Home/Office prior to Ver.1.11.00 allow a remote authenticated attacker with an administrative privilege to execute an arbitrary OS command.
network
low complexity
ate-mahoroba CWE-78
7.2
2023-01-17 CVE-2023-22304 OS Command Injection vulnerability in Pixela Pix-Rt100 Firmware 2.1.1Eq101/2.1.2Eq101
OS command injection vulnerability in PIX-RT100 versions RT100_TEQ_2.1.1_EQ101 and RT100_TEQ_2.1.2_EQ101 allows a network-adjacent attacker who can access product settings to execute an arbitrary OS command.
low complexity
pixela CWE-78
8.0
2023-01-13 CVE-2022-42289 OS Command Injection vulnerability in Nvidia DGX A100 Firmware
NVIDIA BMC contains a vulnerability in SPX REST API, where an authorized attacker can inject arbitrary shell commands, which may lead to code execution, denial of service, information disclosure and data tampering.
network
low complexity
nvidia CWE-78
8.8
2023-01-13 CVE-2022-42290 OS Command Injection vulnerability in Nvidia DGX A100 Firmware
NVIDIA BMC contains a vulnerability in SPX REST API, where an authorized attacker can inject arbitrary shell commands, which may lead to code execution, denial of service, information disclosure and data tampering.
network
low complexity
nvidia CWE-78
8.8
2023-01-13 CVE-2022-42279 OS Command Injection vulnerability in Nvidia DGX A100 Firmware
NVIDIA BMC contains a vulnerability in SPX REST API, where an authorized attacker can inject arbitrary shell commands, which may lead to code execution, denial of service, information disclosure and data tampering.
network
low complexity
nvidia CWE-78
8.8
2023-01-12 CVE-2023-22598 OS Command Injection vulnerability in Inhandnetworks Inrouter302 Firmware and Inrouter615-S Firmware
InHand Networks InRouter 302, prior to version IR302 V3.5.56, and InRouter 615, prior to version InRouter6XX-S-V2.3.0.r5542, contain vulnerability CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection').
network
low complexity
inhandnetworks CWE-78
7.2
2023-01-11 CVE-2022-43390 OS Command Injection vulnerability in Zyxel products
A command injection vulnerability in the CGI program of Zyxel NR7101 firmware prior to V1.15(ACCC.3)C0, which could allow an authenticated attacker to execute some OS commands on a vulnerable device by sending a crafted HTTP request.
network
low complexity
zyxel CWE-78
8.8
2023-01-11 CVE-2022-48252 OS Command Injection vulnerability in Pi.Alert Project Pi.Alert 1.0
The jokob-sk/Pi.Alert fork (before 22.12.20) of Pi.Alert allows Remote Code Execution via nmap_scan.php (scan parameter) OS Command Injection.
network
low complexity
pi-alert-project CWE-78
critical
9.8