Vulnerabilities > Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

DATE CVE VULNERABILITY TITLE RISK
2022-08-25 CVE-2022-36481 OS Command Injection vulnerability in Totolink N350Rt Firmware 9.3.5U.6139B20201216
TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a command injection vulnerability via the ip parameter in the function setDiagnosisCfg.
local
low complexity
totolink CWE-78
7.8
2022-08-25 CVE-2022-36485 OS Command Injection vulnerability in Totolink N350Rt Firmware 9.3.5U.6139B20201216
TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a command injection vulnerability via the hostName parameter in the function setOpModeCfg.
local
low complexity
totolink CWE-78
7.8
2022-08-25 CVE-2022-36486 OS Command Injection vulnerability in Totolink N350Rt Firmware 9.3.5U.6139B20201216
TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a command injection vulnerability via the FileName parameter in the function UploadFirmwareFile.
local
low complexity
totolink CWE-78
7.8
2022-08-25 CVE-2022-36487 OS Command Injection vulnerability in Totolink N350Rt Firmware 9.3.5U.6139B20201216
TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a command injection vulnerability via the command parameter in the function setTracerouteCfg.
local
low complexity
totolink CWE-78
7.8
2022-08-25 CVE-2022-36509 OS Command Injection vulnerability in H3C Gr3200 Firmware Minigr1B0V100R014
H3C GR3200 MiniGR1B0V100R014 was discovered to contain a command injection vulnerability via the param parameter at DelL2tpLNSList.
local
low complexity
h3c CWE-78
7.8
2022-08-25 CVE-2022-36510 OS Command Injection vulnerability in H3C Gr2200 Firmware Minigr1A0V100R014
H3C GR2200 MiniGR1A0V100R014 was discovered to contain a command injection vulnerability via the param parameter at DelL2tpLNSList.
local
low complexity
h3c CWE-78
7.8
2022-08-25 CVE-2022-37070 OS Command Injection vulnerability in H3C Gr-1200W Firmware
H3C GR-1200W MiniGRW1A0V100R006 was discovered to contain a command injection vulnerability via the param parameter at DelL2tpLNSList.
network
low complexity
h3c CWE-78
critical
9.8
2022-08-25 CVE-2022-37076 OS Command Injection vulnerability in Totolink A7000R Firmware 9.1.0U.6115B20201022
TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a command injection vulnerability via the FileName parameter in the function UploadFirmwareFile.
local
low complexity
totolink CWE-78
7.8
2022-08-24 CVE-2022-2234 OS Command Injection vulnerability in Myscada Mypro
An authenticated mySCADA myPRO 8.26.0 user may be able to modify parameters to run commands directly in the operating system.
network
low complexity
myscada CWE-78
8.8
2022-08-24 CVE-2022-36633 OS Command Injection vulnerability in Goteleport Teleport
Teleport 9.3.6 is vulnerable to Command injection leading to Remote Code Execution.
network
low complexity
goteleport CWE-78
8.8