Vulnerabilities (CVE)

Filtered by CWE-77
Angry Yack Logo
Total 3060 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-44837 1 Totolink 2 Cp900, Cp900 Firmware 2025-05-22 N/A 6.3 MEDIUM
TOTOLINK CPE CP900 V6.3c.1144_B20190715 was discovered to contain a command injection vulnerability in the CloudSrvUserdataVersionCheck function via the url or magicid parameters. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
CVE-2025-44836 1 Totolink 2 Cp900, Cp900 Firmware 2025-05-22 N/A 6.3 MEDIUM
TOTOLINK CPE CP900 V6.3c.1144_B20190715 was discovered to contain a command injection vulnerability in the setApRebootScheCfg function via the hour or minute parameters. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
CVE-2024-52022 1 Netgear 8 R6400v2, R6400v2 Firmware, R7000p and 5 more 2025-05-21 N/A 8.0 HIGH
Netgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to contain a command injection vulnerability in the component wlg_adv.cgi via the apmode_gateway parameter. This vulnerability allows attackers to execute arbitrary OS commands via a crafted request.
CVE-2025-44848 1 Totolink 2 Ca600-poe, Ca600-poe Firmware 2025-05-21 N/A 6.5 MEDIUM
TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the msg_process function via the Url parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
CVE-2025-44860 1 Totolink 2 Ca300-poe, Ca300-poe Firmware 2025-05-21 N/A 6.5 MEDIUM
TOTOLINK CA300-POE V6.2c.884_B20180522 was found to contain a command injection vulnerability in the msg_process function via the Port parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
CVE-2025-44861 1 Totolink 2 Ca300-poe, Ca300-poe Firmware 2025-05-21 N/A 6.3 MEDIUM
TOTOLINK CA300-POE V6.2c.884_B20180522 was found to contain a command injection vulnerability in the CloudSrvUserdataVersionCheck function via the url parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
CVE-2025-44862 1 Totolink 2 Ca300-poe, Ca300-poe Firmware 2025-05-21 N/A 6.3 MEDIUM
TOTOLINK CA300-POE V6.2c.884_B20180522 was found to contain a command injection vulnerability in the recvUpgradeNewFw function via the fwUrl parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
CVE-2025-44863 1 Totolink 2 Ca300-poe, Ca300-poe Firmware 2025-05-21 N/A 6.5 MEDIUM
TOTOLINK CA300-POE V6.2c.884_B20180522 was found to contain a command injection vulnerability in the msg_process function via the Url parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
CVE-2024-21117 1 Oracle 1 Outside In Technology 2025-05-21 N/A 5.3 MEDIUM
Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Core). Supported versions that are affected are 8.5.6 and 8.5.7. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Outside In Technology executes to compromise Oracle Outside In Technology. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Outside In Technolo ...

Show More

CVE-2025-2717 1 Dlink 2 Dir-823x, Dir-823x Firmware 2025-05-21 5.8 MEDIUM 4.7 MEDIUM
A vulnerability, which was classified as critical, has been found in D-Link DIR-823X 240126/240802. This issue affects the function sub_41710C of the file /goform/diag_nslookup of the component HTTP POST Request Handler. The manipulation of the argument target_addr leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-1800 1 Dlink 2 Dar-7000, Dar-7000 Firmware 2025-05-21 6.5 MEDIUM 6.3 MEDIUM
A vulnerability has been found in D-Link DAR-7000 3.2 and classified as critical. This vulnerability affects the function get_ip_addr_details of the file /view/vpn/sxh_vpn/sxh_vpnlic.php of the component HTTP POST Request Handler. The manipulation of the argument ethname leads to command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.
CVE-2024-33112 1 Dlink 2 Dir-845l, Dir-845l Firmware 2025-05-21 N/A 7.5 HIGH
D-Link DIR-845L router v1.01KRb03 and before is vulnerable to Command injection via the hnap_main()func.
CVE-2024-33113 1 Dlink 2 Dir-845l, Dir-845l Firmware 2025-05-21 N/A 5.3 MEDIUM
D-LINK DIR-845L <=v1.01KRb03 is vulnerable to Information disclosurey via bsc_sms_inbox.php.
CVE-2024-33344 1 Dlink 2 Dir-822\+, Dir-822\+ Firmware 2025-05-21 N/A 9.8 CRITICAL
D-Link DIR-822+ V1.0.5 was found to contain a command injection in ftext function of upload_firmware.cgi, which allows remote attackers to execute arbitrary commands via shell.
CVE-2024-33342 1 Dlink 2 Dir-822\+, Dir-822\+ Firmware 2025-05-21 N/A 7.5 HIGH
D-Link DIR-822+ V1.0.5 was found to contain a command injection in SetPlcNetworkpwd function of prog.cgi, which allows remote attackers to execute arbitrary commands via shell.
CVE-2022-41870 1 Innovaphone 1 Innovaphone Firmware 2025-05-20 N/A 7.2 HIGH
AP Manager in Innovaphone before 13r2 Service Release 17 allows command injection via a modified service ID during app upload.
CVE-2025-32702 1 Microsoft 2 Visual Studio 2019, Visual Studio 2022 2025-05-19 N/A 7.8 HIGH
Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an unauthorized attacker to execute code locally.
CVE-2025-45798 1 Totolink 2 A950rg, A950rg Firmware 2025-05-19 N/A 9.8 CRITICAL
A command execution vulnerability exists in the TOTOLINK A950RG V4.1.2cu.5204_B20210112. The vulnerability is located in the setNoticeCfg interface within the /lib/cste_modules/system.so library, specifically in the processing of the IpTo parameter.
CVE-2025-4747 2025-05-16 6.5 MEDIUM 6.3 MEDIUM
A vulnerability was found in Bohua NetDragon Firewall 1.0 and classified as critical. This issue affects some unknown processing of the file /systemstatus/ip_status.php. The manipulation of the argument subnet leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
CVE-2022-42160 1 Dlink 6 Covr 1200, Covr 1200 Firmware, Covr 1202 and 3 more 2025-05-16 N/A 8.8 HIGH
D-Link COVR 1200,1202,1203 v1.08 was discovered to contain a command injection vulnerability via the system_time_timezone parameter at function SetNTPServerSettings.
CVE-2024-23749 1 9bis 1 Kitty 2025-05-15 N/A 7.8 HIGH
KiTTY versions 0.76.1.13 and before is vulnerable to command injection via the filename variable, occurs due to insufficient input sanitization and validation, failure to escape special characters, and insecure system calls (at lines 2369-2390). This allows an attacker to add inputs inside the filename variable, leading to arbitrary code execution.
CVE-2024-22107 1 Gttb 1 Gtb Central Console 2025-05-15 N/A 7.2 HIGH
An issue was discovered in GTB Central Console 15.17.1-30814.NG. The method systemSettingsDnsDataAction at /opt/webapp/src/AppBundle/Controller/React/SystemSettingsController.php is vulnerable to command injection via the /old/react/v1/api/system/dns/data endpoint. An authenticated attacker can abuse it to inject an arbitrary command and compromise the platform.
CVE-2022-42897 1 Arraynetworks 15 Ag1000, Ag1000t, Ag1000v5 and 12 more 2025-05-15 N/A 9.8 CRITICAL
Array Networks AG/vxAG with ArrayOS AG before 9.4.0.469 allows unauthenticated command injection that leads to privilege escalation and control of the system. NOTE: ArrayOS AG 10.x is unaffected.
CVE-2022-42161 1 Dlink 6 Covr 1200, Covr 1200 Firmware, Covr 1202 and 3 more 2025-05-15 N/A 8.8 HIGH
D-Link COVR 1200,1202,1203 v1.08 was discovered to contain a command injection vulnerability via the /SetTriggerWPS/PIN parameter at function SetTriggerWPS.
CVE-2022-42906 2 Debian, Powerline Gitstatus Project 2 Debian Linux, Powerline Gitstatus 2025-05-15 N/A 7.8 HIGH
powerline-gitstatus (aka Powerline Gitstatus) before 1.3.2 allows arbitrary code execution. git repositories can contain per-repository configuration that changes the behavior of git, including running arbitrary commands. When using powerline-gitstatus, changing to a directory automatically runs git commands in order to display information about the current repository in the prompt. If an attacker can convince a user to change their current directory to one controlled by the attacker, such as in ...

Show More

CVE-2022-42156 1 Dlink 6 Covr 1200, Covr 1200 Firmware, Covr 1202 and 3 more 2025-05-15 N/A 8.8 HIGH
D-Link COVR 1200,1203 v1.08 was discovered to contain a command injection vulnerability via the tomography_ping_number parameter at function SetNetworkTomographySettings.
CVE-2024-38831 1 Vmware 2 Aria Operations, Cloud Foundation 2025-05-14 N/A 7.8 HIGH
VMware Aria Operations contains a local privilege escalation vulnerability.  A malicious actor with local administrative privileges can insert malicious commands into the properties file to escalate privileges to  a root user on the appliance running VMware Aria Operations.
CVE-2025-4121 1 Netgear 2 Jwnr2000v2, Jwnr2000v2 Firmware 2025-05-13 6.5 MEDIUM 6.3 MEDIUM
A vulnerability was found in Netgear JWNR2000v2 1.0.0.11. It has been declared as critical. Affected by this vulnerability is the function cmd_wireless. The manipulation of the argument host leads to command injection. The attack can be launched remotely. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2025-4340 1 Dlink 4 Dir-806, Dir-806 Firmware, Dir-890l and 1 more 2025-05-13 6.5 MEDIUM 6.3 MEDIUM
A vulnerability classified as critical has been found in D-Link DIR-890L and DIR-806A1 up to 100CNb11/108B03. Affected is the function sub_175C8 of the file /htdocs/soap.cgi. The manipulation leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.
CVE-2025-4341 1 Dlink 2 Dir-880l, Dir-880l Firmware 2025-05-13 6.5 MEDIUM 6.3 MEDIUM
A vulnerability classified as critical was found in D-Link DIR-880L up to 104WWb01. Affected by this vulnerability is the function sub_16570 of the file /htdocs/ssdpcgi of the component Request Header Handler. The manipulation of the argument HTTP_ST/REMOTE_ADDR/REMOTE_PORT/SERVER_ID leads to command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.
CVE-2025-4443 1 Dlink 2 Dir-605l, Dir-605l Firmware 2025-05-13 6.5 MEDIUM 6.3 MEDIUM
A vulnerability was found in D-Link DIR-605L 2.13B01. It has been rated as critical. This issue affects the function sub_454F2C. The manipulation of the argument sysCmd leads to command injection. The attack may be initiated remotely. The vendor was contacted early about this disclosure. This vulnerability only affects products that are no longer supported by the maintainer.
CVE-2025-4445 1 Dlink 2 Dir-605l, Dir-605l Firmware 2025-05-13 6.5 MEDIUM 6.3 MEDIUM
A vulnerability classified as critical has been found in D-Link DIR-605L 2.13B01. Affected is the function wake_on_lan. The manipulation of the argument mac leads to command injection. It is possible to launch the attack remotely. The vendor was contacted early about this disclosure. This vulnerability only affects products that are no longer supported by the maintainer.
CVE-2025-45492 1 Netgear 2 Ex8000, Ex8000 Firmware 2025-05-13 N/A 9.8 CRITICAL
Netgear EX8000 V1.0.0.126 is vulnerable to Command Injection via the Iface parameter in the action_wireless function.
CVE-2025-45491 1 Linksys 2 E5600, E5600 Firmware 2025-05-13 N/A 9.8 CRITICAL
Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the username parameter.
CVE-2025-45490 1 Linksys 2 E5600, E5600 Firmware 2025-05-13 N/A 9.8 CRITICAL
Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the password parameter.
CVE-2025-45489 1 Linksys 2 E5600, E5600 Firmware 2025-05-13 N/A 9.8 CRITICAL
Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the hostname parameter.
CVE-2025-45488 1 Linksys 2 E5600, E5600 Firmware 2025-05-13 N/A 9.8 CRITICAL
Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the mailex parameter.
CVE-2025-45487 1 Linksys 2 E5600, E5600 Firmware 2025-05-13 N/A 9.8 CRITICAL
Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.InternetConnection function.
CVE-2025-4453 1 Dlink 2 Dir-619l, Dir-619l Firmware 2025-05-13 6.5 MEDIUM 6.3 MEDIUM
A vulnerability was found in D-Link DIR-619L 2.04B04. It has been classified as critical. This affects the function formSysCmd. The manipulation of the argument sysCmd leads to command injection. It is possible to initiate the attack remotely. The vendor was contacted early about this disclosure. This vulnerability only affects products that are no longer supported by the maintainer.
CVE-2025-4454 1 Dlink 2 Dir-619l, Dir-619l Firmware 2025-05-13 6.5 MEDIUM 6.3 MEDIUM
A vulnerability was found in D-Link DIR-619L 2.04B04. It has been declared as critical. This vulnerability affects the function wake_on_lan. The manipulation of the argument mac leads to command injection. The attack can be initiated remotely. The vendor was contacted early about this disclosure. This vulnerability only affects products that are no longer supported by the maintainer.