Vulnerability index

Browse CVEs

3,666 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
Ac9 Firmware CRITICAL 9.8
CVE-2025-45042

Tenda AC9 v15.03.05.14 was discovered to contain a command injection vulnerability via the Telnet function.

No fix yet
Fix from $2,300 2025-05-05
Gefen Webfwc MEDIUM 6.5
CVE-2025-25504

An issue in the /usr/local/bin/jncs.sh script of Gefen WebFWC (In AV over IP products) v1.85h, v1.86v, and v1.70 allows attackers with network access…

No fix yet
Fix from $1,600 2025-05-05
A950rg Firmware CRITICAL 9.8
CVE-2025-45800

TOTOLINK A950RG V4.1.2cu.5204_B20210112 contains a command execution vulnerability in the setDeviceName interface of the /lib/cste_modules/global.so …

No fix yet
Fix from $2,300 2025-05-02
Wl Wn530h4 Firmware CRITICAL 9.8
CVE-2025-44868

Wavlink WL-WN530H4 20220801 was found to contain a command injection vulnerability in the ping_test function of the adm.cgi via the pingIp parameter.…

No fix yet
Fix from $2,300 2025-05-02
Ac9 Firmware CRITICAL 9.8
CVE-2025-44872

Tenda AC9 V15.03.06.42_multi was found to contain a command injection vulnerability in the formsetUsbUnload function via the deviceName parameter. Th…

No fix yet
Fix from $2,300 2025-05-02
Ac9 Firmware CRITICAL 9.8
CVE-2025-44877

Tenda AC9 V15.03.06.42_multi was found to contain a command injection vulnerability in the formSetSambaConf function via the usbname parameter. This …

No fix yet
Fix from $2,300 2025-05-02
Rx2 Pro Firmware HIGH 8.8
CVE-2025-46625

Lack of input validation/sanitization in the 'setLanCfg' API endpoint in httpd in the Tenda RX2 Pro 16.03.30.14 allows a remote attacker that is auth…

Mitigation only
Fix from $1,950 2025-05-01
W20e Firmware MEDIUM 6.3
CVE-2025-44865

Tenda W20E V15.11.0.6 was found to contain a command injection vulnerability in the formSetDebugCfg function via the enable parameter. This vulnerabi…

No fix yet
Fix from $1,600 2025-05-01
W20e Firmware MEDIUM 6.3
CVE-2025-44866

Tenda W20E V15.11.0.6 was found to contain a command injection vulnerability in the formSetDebugCfg function via the level parameter. This vulnerabil…

No fix yet
Fix from $1,600 2025-05-01
W20e Firmware MEDIUM 6.3
CVE-2025-44867

Tenda W20E V15.11.0.6 was found to contain a command injection vulnerability in the formSetNetCheckTools function via the hostName parameter. This vu…

No fix yet
Fix from $1,600 2025-05-01
Ca300 Poe Firmware MEDIUM 6.5
CVE-2025-44860

TOTOLINK CA300-POE V6.2c.884_B20180522 was found to contain a command injection vulnerability in the msg_process function via the Port parameter. Thi…

No fix yet
Fix from $1,600 2025-05-01
Ca300 Poe Firmware MEDIUM 6.3
CVE-2025-44861

TOTOLINK CA300-POE V6.2c.884_B20180522 was found to contain a command injection vulnerability in the CloudSrvUserdataVersionCheck function via the ur…

No fix yet
Fix from $1,600 2025-05-01
Ca300 Poe Firmware MEDIUM 6.3
CVE-2025-44862

TOTOLINK CA300-POE V6.2c.884_B20180522 was found to contain a command injection vulnerability in the recvUpgradeNewFw function via the fwUrl paramete…

No fix yet
Fix from $1,600 2025-05-01
Ca300 Poe Firmware MEDIUM 6.5
CVE-2025-44863

TOTOLINK CA300-POE V6.2c.884_B20180522 was found to contain a command injection vulnerability in the msg_process function via the Url parameter. This…

No fix yet
Fix from $1,600 2025-05-01
W20e Firmware MEDIUM 6.3
CVE-2025-44864

Tenda W20E V15.11.0.6 was found to contain a command injection vulnerability in the formSetDebugCfg function via the module parameter. This vulnerabi…

No fix yet
Fix from $1,600 2025-05-01
Ca600 Poe Firmware MEDIUM 6.3
CVE-2025-44847

TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the setWebWlanIdx function via the webWlanIdx param…

No fix yet
Fix from $1,600 2025-05-01
Ca600 Poe Firmware MEDIUM 6.5
CVE-2025-44848

TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the msg_process function via the Url parameter. Thi…

No fix yet
Fix from $1,600 2025-05-01
Ca600 Poe Firmware MEDIUM 6.5
CVE-2025-44839

TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the CloudSrvUserdataVersionCheck function via the m…

No fix yet
Fix from $1,600 2025-05-01
Ca600 Poe Firmware MEDIUM 6.5
CVE-2025-44840

TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the CloudSrvUserdataVersionCheck function via the s…

No fix yet
Fix from $1,600 2025-05-01
Ca600 Poe Firmware MEDIUM 6.5
CVE-2025-44841

TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the CloudSrvUserdataVersionCheck function via the v…

No fix yet
Fix from $1,600 2025-05-01
Ca600 Poe Firmware MEDIUM 6.5
CVE-2025-44842

TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the msg_process function via the Port parameter. Th…

No fix yet
Fix from $1,600 2025-05-01
Ca600 Poe Firmware MEDIUM 6.5
CVE-2025-44843

TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the CloudSrvUserdataVersionCheck function via the u…

No fix yet
Fix from $1,600 2025-05-01
Ca600 Poe Firmware MEDIUM 6.5
CVE-2025-44844

TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the setUpgradeFW function via the FileName paramete…

No fix yet
Fix from $1,600 2025-05-01
Ca600 Poe Firmware MEDIUM 6.5
CVE-2025-44845

TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the NTPSyncWithHost function via the hostTime param…

No fix yet
Fix from $1,600 2025-05-01
Ca600 Poe Firmware MEDIUM 6.3
CVE-2025-44846

TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the recvUpgradeNewFw function via the fwUrl paramet…

No fix yet
Fix from $1,600 2025-05-01
Cp900 Firmware MEDIUM 6.3
CVE-2025-44836

TOTOLINK CPE CP900 V6.3c.1144_B20190715 was discovered to contain a command injection vulnerability in the setApRebootScheCfg function via the hour o…

No fix yet
Fix from $1,600 2025-05-01
Cp900 Firmware MEDIUM 6.3
CVE-2025-44837

TOTOLINK CPE CP900 V6.3c.1144_B20190715 was discovered to contain a command injection vulnerability in the CloudSrvUserdataVersionCheck function via …

No fix yet
Fix from $1,600 2025-05-01
Cp900 Firmware MEDIUM 6.3
CVE-2025-44838

TOTOLINK CPE CP900 V6.3c.1144_B20190715 was discovered to contain a command injection vulnerability in the setUploadUserData function via the FileNam…

No fix yet
Fix from $1,600 2025-05-01
Dir 816 A2 Firmware MEDIUM 6.3
CVE-2025-44835

D-Link DIR-816 A2V1.1.0B05 was found to contain a command injection in iptablesWebsFilterRun, which allows remote attackers to execute arbitrary comm…

No fix yet
Fix from $1,600 2025-05-01
Cp900 Firmware MEDIUM 6.3
CVE-2025-44854

TOTOLINK CP900 V6.3c.1144_B20190715 was found to contain a command injection vulnerability in the setUpgradeUboot function via the FileName parameter…

No fix yet
Fix from $1,600 2025-05-01