Filtered by CWE-77
Total 3832 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2021-4304 1 Ulcc-core Project 1 Ulcc-core 2025-05-28 6.3 Medium
A vulnerability was found in eprintsug ulcc-core. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file cgi/toolbox/toolbox. The manipulation of the argument password leads to command injection. The attack can be launched remotely. The patch is named 811edaae81eb044891594f00062a828f51b22cb1. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-217447.
CVE-2025-44864 1 Tenda 2 W20e, W20e Firmware 2025-05-27 6.3 Medium
Tenda W20E V15.11.0.6 was found to contain a command injection vulnerability in the formSetDebugCfg function via the module parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
CVE-2025-44865 1 Tenda 2 W20e, W20e Firmware 2025-05-27 6.3 Medium
Tenda W20E V15.11.0.6 was found to contain a command injection vulnerability in the formSetDebugCfg function via the enable parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
CVE-2025-44866 1 Tenda 2 W20e, W20e Firmware 2025-05-27 6.3 Medium
Tenda W20E V15.11.0.6 was found to contain a command injection vulnerability in the formSetDebugCfg function via the level parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
CVE-2025-44867 1 Tenda 2 W20e, W20e Firmware 2025-05-27 6.3 Medium
Tenda W20E V15.11.0.6 was found to contain a command injection vulnerability in the formSetNetCheckTools function via the hostName parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
CVE-2024-37642 1 Trendnet 2 Tew-814dap, Tew-814dap Firmware 2025-05-27 9.1 Critical
TRENDnet TEW-814DAP v1_(FW1.01B01) was discovered to contain a command injection vulnerability via the ipv4_ping, ipv6_ping parameter at /formSystemCheck .
CVE-2024-38903 1 H3c 2 Magic R230, Magic R230 Firmware 2025-05-27 4.1 Medium
H3C Magic R230 V100R002's udpserver opens port 9034, allowing attackers to execute arbitrary commands.
CVE-2025-46625 1 Tenda 2 Rx2 Pro, Rx2 Pro Firmware 2025-05-27 8.8 High
Lack of input validation/sanitization in the 'setLanCfg' API endpoint in httpd in the Tenda RX2 Pro 16.03.30.14 allows a remote attacker that is authorized to the web management portal to gain root shell access to the device by sending a crafted web request. This is persistent because the command injection is saved in the configuration of the device.
CVE-2025-44877 1 Tenda 2 Ac9, Ac9 Firmware 2025-05-27 9.8 Critical
Tenda AC9 V15.03.06.42_multi was found to contain a command injection vulnerability in the formSetSambaConf function via the usbname parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
CVE-2025-44872 1 Tenda 2 Ac9, Ac9 Firmware 2025-05-27 9.8 Critical
Tenda AC9 V15.03.06.42_multi was found to contain a command injection vulnerability in the formsetUsbUnload function via the deviceName parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
CVE-2024-55062 1 Easyvirt 2 Co2scope, Dcscope 2025-05-24 9.8 Critical
Code Injection vulnerability in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote unauthenticated attackers to execute arbitrary code to /api/license/sendlicense/.
CVE-2025-4851 1 Totolink 2 N300rh, N300rh Firmware 2025-05-24 6.3 Medium
A vulnerability classified as critical was found in TOTOLINK N300RH 6.1c.1390_B20191101. This vulnerability affects the function setUploadUserData of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument FileName leads to command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-4850 1 Totolink 2 N300rh, N300rh Firmware 2025-05-24 6.3 Medium
A vulnerability classified as critical has been found in TOTOLINK N300RH 6.1c.1390_B20191101. This affects the function setUnloadUserData of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument plugin_name leads to command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-4849 1 Totolink 2 N300rh, N300rh Firmware 2025-05-24 6.3 Medium
A vulnerability was found in TOTOLINK N300RH 6.1c.1390_B20191101. It has been rated as critical. Affected by this issue is the function CloudACMunualUpdateUserdata of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument url leads to command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-44176 1 Tenda 2 Fh451, Fh451 Firmware 2025-05-23 6.5 Medium
Tenda FH451 V1.0.0.9 is vulnerable to Remote Code Execution in the formSafeEmailFilter function.
CVE-2022-40100 1 Tenda 2 I9, I9 Firmware 2025-05-22 9.8 Critical
Tenda i9 v1.0.0.8(3828) was discovered to contain a command injection vulnerability via the FormexeCommand function.
CVE-2023-6572 1 Gradio Project 1 Gradio 2025-05-22 8.1 High
Command Injection in GitHub repository gradio-app/gradio prior to main.
CVE-2025-44854 1 Totolink 2 Cp900, Cp900 Firmware 2025-05-22 6.3 Medium
TOTOLINK CP900 V6.3c.1144_B20190715 was found to contain a command injection vulnerability in the setUpgradeUboot function via the FileName parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
CVE-2025-44847 1 Totolink 2 Ca600-poe, Ca600-poe Firmware 2025-05-22 6.3 Medium
TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the setWebWlanIdx function via the webWlanIdx parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
CVE-2025-44846 1 Totolink 2 Ca600-poe, Ca600-poe Firmware 2025-05-22 6.3 Medium
TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the recvUpgradeNewFw function via the fwUrl parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.