CVE-2024-21488High· 7.3▾ TwilightVersions of the package network before 0.7.0 are vulnerable to Arbitrary Command Injection due to use of the child_process exec function without input sanitization. If (attacker-controlled) user input is given to the mac_address_for func…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 40.2 · likelihood 0.7 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
3.2%
3.2% → 3.3%
Versions of the package network before 0.7.0 are vulnerable to Arbitrary Command Injection due to use of the child_process exec function without input sanitization. If (attacker-controlled) user input is given to the mac_address_for function of the package, it is possible for the attacker to execute arbitrary commands on the operating system that this package is being run on.
network < 0.7.0Upgrade past the affected range:
network 0.7.0Connected by shared product, vendor, weakness, or advisory.
CVE-2025-13799Medium· 6.3A vulnerability has been found in ADSLR NBR1005GPEV2 250814-r037c
CVE-2025-13797Medium· 6.3A vulnerability was detected in ADSLR B-QE2W401 250814-r037c
CVE-2019-25029Critical· 9.8In Versa Director, the command injection is an attack in which the goal is execution of arbitrary commands on the host operating system via a vulnerable application
CVE-2018-19949Critical· 9.8If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands
CVE-2024-55956Critical· 9.8In Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.8.0.24, an unauthenticated user can import and execute arbitrary Bash or PowerShell commands on the host system by leveraging the default settings of the Aut…
CVE-2025-10035Critical· 10.0A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection.