Vulnerabilities (CVE)

Filtered by CWE-77
Total 2267 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-44867 1 Tenda 2 W20e, W20e Firmware 2025-05-27 N/A 6.3 MEDIUM
Tenda W20E V15.11.0.6 was found to contain a command injection vulnerability in the formSetNetCheckTools function via the hostName parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
CVE-2024-37642 1 Trendnet 2 Tew-814dap, Tew-814dap Firmware 2025-05-27 N/A 9.1 CRITICAL
TRENDnet TEW-814DAP v1_(FW1.01B01) was discovered to contain a command injection vulnerability via the ipv4_ping, ipv6_ping parameter at /formSystemCheck .
CVE-2024-38903 1 H3c 2 Magic R230, Magic R230 Firmware 2025-05-27 N/A 4.1 MEDIUM
H3C Magic R230 V100R002's udpserver opens port 9034, allowing attackers to execute arbitrary commands.
CVE-2025-46625 1 Tenda 2 Rx2 Pro, Rx2 Pro Firmware 2025-05-27 N/A 8.8 HIGH
Lack of input validation/sanitization in the 'setLanCfg' API endpoint in httpd in the Tenda RX2 Pro 16.03.30.14 allows a remote attacker that is authorized to the web management portal to gain root shell access to the device by sending a crafted web request. This is persistent because the command injection is saved in the configuration of the device.
CVE-2025-44877 1 Tenda 2 Ac9, Ac9 Firmware 2025-05-27 N/A 9.8 CRITICAL
Tenda AC9 V15.03.06.42_multi was found to contain a command injection vulnerability in the formSetSambaConf function via the usbname parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
CVE-2025-44872 1 Tenda 2 Ac9, Ac9 Firmware 2025-05-27 N/A 9.8 CRITICAL
Tenda AC9 V15.03.06.42_multi was found to contain a command injection vulnerability in the formsetUsbUnload function via the deviceName parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
CVE-2024-55062 1 Easyvirt 2 Co2scope, Dcscope 2025-05-24 N/A 9.8 CRITICAL
Code Injection vulnerability in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote unauthenticated attackers to execute arbitrary code to /api/license/sendlicense/.
CVE-2025-4851 1 Totolink 2 N300rh, N300rh Firmware 2025-05-24 6.5 MEDIUM 6.3 MEDIUM
A vulnerability classified as critical was found in TOTOLINK N300RH 6.1c.1390_B20191101. This vulnerability affects the function setUploadUserData of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument FileName leads to command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-4850 1 Totolink 2 N300rh, N300rh Firmware 2025-05-24 6.5 MEDIUM 6.3 MEDIUM
A vulnerability classified as critical has been found in TOTOLINK N300RH 6.1c.1390_B20191101. This affects the function setUnloadUserData of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument plugin_name leads to command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-4849 1 Totolink 2 N300rh, N300rh Firmware 2025-05-24 6.5 MEDIUM 6.3 MEDIUM
A vulnerability was found in TOTOLINK N300RH 6.1c.1390_B20191101. It has been rated as critical. Affected by this issue is the function CloudACMunualUpdateUserdata of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument url leads to command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-44176 1 Tenda 2 Fh451, Fh451 Firmware 2025-05-23 N/A 6.5 MEDIUM
Tenda FH451 V1.0.0.9 is vulnerable to Remote Code Execution in the formSafeEmailFilter function.
CVE-2025-5106 2025-05-23 7.5 HIGH 7.3 HIGH
A vulnerability was found in Fujian Kelixun 1.0. It has been classified as critical. This affects an unknown part of the file /app/fax/fax_view.php of the component Filename Handler. The manipulation of the argument fax_file leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2025-4008 2025-05-23 N/A N/A
The Meteobridge web interface let meteobridge administrator manage their weather station data collection and administer their meteobridge system through a web application written in CGI shell scripts and C. This web interface exposes an endpoint that is vulnerable to command injection. Remote unauthenticated attackers can gain arbitrary command execution with elevated privileges ( root ) on affected devices.
CVE-2022-40100 1 Tenda 2 I9, I9 Firmware 2025-05-22 N/A 9.8 CRITICAL
Tenda i9 v1.0.0.8(3828) was discovered to contain a command injection vulnerability via the FormexeCommand function.
CVE-2025-44854 1 Totolink 2 Cp900, Cp900 Firmware 2025-05-22 N/A 6.3 MEDIUM
TOTOLINK CP900 V6.3c.1144_B20190715 was found to contain a command injection vulnerability in the setUpgradeUboot function via the FileName parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
CVE-2025-44847 1 Totolink 2 Ca600-poe, Ca600-poe Firmware 2025-05-22 N/A 6.3 MEDIUM
TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the setWebWlanIdx function via the webWlanIdx parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
CVE-2025-44846 1 Totolink 2 Ca600-poe, Ca600-poe Firmware 2025-05-22 N/A 6.3 MEDIUM
TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the recvUpgradeNewFw function via the fwUrl parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
CVE-2025-44845 1 Totolink 2 Ca600-poe, Ca600-poe Firmware 2025-05-22 N/A 6.5 MEDIUM
TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the NTPSyncWithHost function via the hostTime parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
CVE-2025-44844 1 Totolink 2 Ca600-poe, Ca600-poe Firmware 2025-05-22 N/A 6.5 MEDIUM
TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the setUpgradeFW function via the FileName parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
CVE-2025-44843 1 Totolink 2 Ca600-poe, Ca600-poe Firmware 2025-05-22 N/A 6.5 MEDIUM
TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the CloudSrvUserdataVersionCheck function via the url parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.