VulnSea

CWE-77

CVEs classified under CWE-77, newest first.

271 CVEsRSS

CVE-2025-9586Medium· 6.3
1y ago

A vulnerability was identified in Comfast CF-N1 2.6.0

A vulnerability was identified in Comfast CF-N1 2.6.0. This vulnerability affects the function wireless_device_dissoc of the file /usr/bin/webmgnt. Such manipulation of the argument mac leads to command injection. The attack may be perfo…

▾ Sunlitcomfast · cf-n1_firmwareEPSS 8.3%via NVD
CVE-2025-9585Medium· 6.3
1y ago

A vulnerability was determined in Comfast CF-N1 2.6.0

A vulnerability was determined in Comfast CF-N1 2.6.0. This affects the function wifilith_delete_pic_file of the file /usr/bin/webmgnt. This manipulation of the argument portal_delete_picname causes command injection. The attack is possi…

▾ Sunlitcomfast · cf-n1_firmwareEPSS 5.1%via NVD
CVE-2025-9584Medium· 6.3
1y ago

A vulnerability was found in Comfast CF-N1 2.6.0

A vulnerability was found in Comfast CF-N1 2.6.0. Affected by this issue is the function update_interface_png of the file /usr/bin/webmgnt. The manipulation of the argument interface/display_name results in command injection. The attack …

▾ Sunlitcomfast · cf-n1_firmwareEPSS 8.3%via NVD
CVE-2025-9583Medium· 6.3
1y ago

A vulnerability has been found in Comfast CF-N1 2.6.0

A vulnerability has been found in Comfast CF-N1 2.6.0. Affected by this vulnerability is the function ping_config of the file /usr/bin/webmgnt. The manipulation leads to command injection. Remote exploitation of the attack is possible. T…

▾ Sunlitcomfast · cf-n1_firmwareEPSS 5.1%via NVD
CVE-2025-9582Medium· 6.3
1y ago

A flaw has been found in Comfast CF-N1 2.6.0

A flaw has been found in Comfast CF-N1 2.6.0. Affected is the function ntp_timezone of the file /usr/bin/webmgnt. Executing manipulation of the argument timestr can lead to command injection. The attack may be launched remotely. The expl…

▾ Sunlitcomfast · cf-n1_firmwareEPSS 5.3%via NVD
CVE-2025-9581Medium· 6.3
1y ago

A vulnerability was detected in Comfast CF-N1 2.6.0

A vulnerability was detected in Comfast CF-N1 2.6.0. This impacts the function multi_pppoe of the file /usr/bin/webmgnt. Performing manipulation of the argument phy_interface results in command injection. The attack may be initiated remo…

▾ Sunlitcomfast · cf-n1_firmwareEPSS 5.3%via NVD
CVE-2025-9580Medium· 6.3
1y ago

A security vulnerability has been detected in LB-LINK BL-X26 1.2.8

A security vulnerability has been detected in LB-LINK BL-X26 1.2.8. This affects an unknown function of the file /goform/set_blacklist of the component HTTP Handler. Such manipulation of the argument mac leads to os command injection. Th…

▾ Sunlitlb-link · bl-x26_firmwareEPSS 6.7%via NVD
CVE-2025-9579Medium· 6.3
1y ago

A weakness has been identified in LB-LINK BL-X26 1.2.8

A weakness has been identified in LB-LINK BL-X26 1.2.8. The impacted element is an unknown function of the file /goform/set_hidessid_cfg of the component HTTP Handler. This manipulation of the argument enable causes os command injection.…

▾ Sunlitb-link · bl-x26_firmwareEPSS 6.9%via NVD
CVE-2025-23170Medium· 6.7
1y ago

The Versa Director SD-WAN orchestration platform includes functionality to initiate SSH sessions to remote CPEs and the Director shell via Shell-In-A-Box

The Versa Director SD-WAN orchestration platform includes functionality to initiate SSH sessions to remote CPEs and the Director shell via Shell-In-A-Box. The underlying Python script, shell-connect.py, is vulnerable to command injection…

▾ SunlitEPSS 0.59%via NVD
CVE-2024-55956Critical· 9.8CISA KEVPoC
1y ago

In Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.8.0.24, an unauthenticated user can import and execute arbitrary Bash or PowerShell commands on the host system by leveraging the default settings of the Aut…

In Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.8.0.24, an unauthenticated user can import and execute arbitrary Bash or PowerShell commands on the host system by leveraging the default settings of the Aut…

▾ Hadalcleo · harmonyEPSS 94%via NVD
CVE-2024-4944High· 7.8
2y ago

A local privilege escalation vlnerability in the WatchGuard Mobile VPN with SSL client on Windows enables a local user to execute arbitrary commands with elevated privileged.

A local privilege escalation vlnerability in the WatchGuard Mobile VPN with SSL client on Windows enables a local user to execute arbitrary commands with elevated privileged.

▾ Twilightwatchguard · mobile_vpn_with_sslEPSS 0.34%via NVD
CVE-2024-3154High· 7.2
2y ago

A flaw was found in cri-o, where an arbitrary systemd property can be injected via a Pod annotation

A flaw was found in cri-o, where an arbitrary systemd property can be injected via a Pod annotation. Any user who can create a pod with an arbitrary annotation may perform an arbitrary action on the host system.

▾ Twilightcri-o · github.com/cri-o/cri-oEPSS 1.4%via NVD
CVE-2024-21488High· 7.3
2y ago

Versions of the package network before 0.7.0 are vulnerable to Arbitrary Command Injection due to use of the child_process exec function without input sanitization

Versions of the package network before 0.7.0 are vulnerable to Arbitrary Command Injection due to use of the child_process exec function without input sanitization. If (attacker-controlled) user input is given to the mac_address_for func…

▾ Twilightforkhq · networkEPSS 3.3%via NVD
CVE-2024-21887Critical· 9.1CISA KEV0dayPoC
2y ago

A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send specially crafted requests and execute arbitrary commands on the…

A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send specially crafted requests and execute arbitrary commands on the…

▾ Hadalivanti · connect_secureEPSS 100%via NVD
CVE-2023-39809Critical· 9.8
3y ago

N.V.K.INTER CO., LTD

N.V.K.INTER CO., LTD. (NVK) iBSG v3.5 was discovered to contain an OS command injection vulnerability via shell metacharacters in the system_hostname parameter at /manage/network-basic.php.

▾ Midnightnvki · intelligent_broadband_subscriber_gatewayEPSS 1.5%via NVD
CVE-2023-2378High· 7.2
3y ago

A flaw has been found in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6

A flaw has been found in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6. This affects an unknown function of the component Web Management Interface. This manipulation of the argument suffix-rate-up causes command injection. The attack may be…

▾ Twilightui · er-x_firmwareEPSS 7.6%via NVD
CVE-2023-2377High· 7.2
3y ago

A vulnerability was detected in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6

A vulnerability was detected in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6. The impacted element is an unknown function of the component Web Management Interface. The manipulation of the argument Name results in command injection. The at…

▾ Twilightui · er-x_firmwareEPSS 7.6%via NVD
CVE-2023-2376High· 7.2
3y ago

A security vulnerability has been detected in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6

A security vulnerability has been detected in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6. The affected element is an unknown function of the component Web Management Interface. The manipulation of the argument dpi leads to command inject…

▾ Twilightui · er-x_firmwareEPSS 7.6%via NVD
CVE-2023-2375High· 7.2PoC
3y ago

A weakness has been identified in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6

A weakness has been identified in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6. Impacted is an unknown function of the component Web Management Interface. Executing a manipulation of the argument src can lead to command injection. It is po…

▾ Midnightui · er-x_firmwareEPSS 9.3%via NVD
CVE-2023-2374High· 7.2
3y ago

A security flaw has been discovered in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6

A security flaw has been discovered in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6. This issue affects some unknown processing of the component Web Management Interface. Performing a manipulation of the argument ecn-down results in comman…

▾ Twilightui · er-x_firmwareEPSS 6.9%via NVD
CVE-2023-2373High· 7.2
3y ago

A vulnerability was identified in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6

A vulnerability was identified in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6. This vulnerability affects unknown code of the component Web Management Interface. Such manipulation of the argument ecn-up leads to command injection. The att…

▾ Twilightui · edgemax_edgerouter_firmwareEPSS 7.6%via NVD
CVE-2021-43163Critical· 9.8
4y ago

A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW_3.0(1)B11P55 via the checkNet function in /cgi-bin/luci/api/auth.

A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW_3.0(1)B11P55 via the checkNet function in /cgi-bin/luci/api/auth.

▾ Midnightruijienetworks · reyeeosEPSS 2.1%via NVD
CVE-2021-43162High· 8.8
4y ago

A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW_3.0(1)B11P55 via the runPackDiagnose function in /cgi-bin/luci/api/diagnose.

A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW_3.0(1)B11P55 via the runPackDiagnose function in /cgi-bin/luci/api/diagnose.

▾ Twilightruijienetworks · reyeeosEPSS 1.8%via NVD
CVE-2021-43161High· 8.8
4y ago

A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW_3.0(1)B11P55 via the doSwitchApi function in /cgi-bin/luci/api/switch.

A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW_3.0(1)B11P55 via the doSwitchApi function in /cgi-bin/luci/api/switch.

▾ Twilightruijienetworks · reyeeosEPSS 1.8%via NVD
CVE-2021-43160High· 8.8
4y ago

A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW_3.0(1)B11P55 via the switchFastDhcp function in /cgi-bin/luci/api/diagnose.

A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW_3.0(1)B11P55 via the switchFastDhcp function in /cgi-bin/luci/api/diagnose.

▾ Twilightruijienetworks · reyeeosEPSS 1.8%via NVD
CVE-2021-43159High· 8.8
4y ago

A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW_3.0(1)B11P55 via the setSessionTime function in /cgi-bin/luci/api/common..

A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW_3.0(1)B11P55 via the setSessionTime function in /cgi-bin/luci/api/common..

▾ Twilightruijienetworks · reyeeosEPSS 1.9%via NVD
CVE-2021-44620Critical· 9.8
4y ago

A Command Injection vulnerability exits in TOTOLINK A3100R <=V4.1.2cu.5050_B20200504 in adm/ntm.asp via the hosTime parameters.

A Command Injection vulnerability exits in TOTOLINK A3100R <=V4.1.2cu.5050_B20200504 in adm/ntm.asp via the hosTime parameters.

▾ Midnighttotolink · a3100r_firmwareEPSS 1.4%via NVD
CVE-2021-42638High· 8.1
4y ago

PrinterLogic Web Stack versions 19.1.1.13 SP9 and below do not sanitize user input resulting in pre-auth remote code execution.

PrinterLogic Web Stack versions 19.1.1.13 SP9 and below do not sanitize user input resulting in pre-auth remote code execution.

▾ Twilightprinterlogic · web_stackEPSS 5.5%via NVD
CVE-2019-25029Critical· 9.8
5y ago

In Versa Director, the command injection is an attack in which the goal is execution of arbitrary commands on the host operating system via a vulnerable application

In Versa Director, the command injection is an attack in which the goal is execution of arbitrary commands on the host operating system via a vulnerable application. Command injection attacks are possible when an application passes unsaf…

▾ Midnightversa-networks · versa_directorEPSS 2.4%via NVD
CVE-2018-19949Critical· 9.8CISA KEV0day
5y ago

If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands

If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. QNAP has already fixed the issue in the following QTS versions. QTS 4.4.2.1231 on build 20200302; QTS 4.4.1.1201 on build 20200130…

▾ Hadalqnap · qtsEPSS 28%via NVD
CWE-77 vulnerabilities (CVEs) — page 9 · VulnSea