Vulnerability index

Browse CVEs

3,666 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Command InjectionCWE-77 × clear
CRITICAL 9.8 CVE-2025-45042 Tenda AC9 v15.03.05.14 was discovered to contain a command injection vulnerability via the Telnet function. Ac9 Firmware No fix yet Fix from $2,3002025-05-05 MEDIUM 6.5 CVE-2025-25504 An issue in the /usr/local/bin/jncs.sh script of Gefen WebFWC (In AV over IP products) v1.85h, v1.86v, and v1.70 allows attackers with network access… Gefen Webfwc No fix yet Fix from $1,6002025-05-05 CRITICAL 9.8 CVE-2025-45800 TOTOLINK A950RG V4.1.2cu.5204_B20210112 contains a command execution vulnerability in the setDeviceName interface of the /lib/cste_modules/global.so … A950rg Firmware No fix yet Fix from $2,3002025-05-02 CRITICAL 9.8 CVE-2025-44868 Wavlink WL-WN530H4 20220801 was found to contain a command injection vulnerability in the ping_test function of the adm.cgi via the pingIp parameter.… Wl Wn530h4 Firmware No fix yet Fix from $2,3002025-05-02 CRITICAL 9.8 CVE-2025-44872 Tenda AC9 V15.03.06.42_multi was found to contain a command injection vulnerability in the formsetUsbUnload function via the deviceName parameter. Th… Ac9 Firmware No fix yet Fix from $2,3002025-05-02 CRITICAL 9.8 CVE-2025-44877 Tenda AC9 V15.03.06.42_multi was found to contain a command injection vulnerability in the formSetSambaConf function via the usbname parameter. This … Ac9 Firmware No fix yet Fix from $2,3002025-05-02 HIGH 8.8 CVE-2025-46625 Lack of input validation/sanitization in the 'setLanCfg' API endpoint in httpd in the Tenda RX2 Pro 16.03.30.14 allows a remote attacker that is auth… Rx2 Pro Firmware Mitigation only Fix from $1,9502025-05-01 MEDIUM 6.3 CVE-2025-44865 Tenda W20E V15.11.0.6 was found to contain a command injection vulnerability in the formSetDebugCfg function via the enable parameter. This vulnerabi… W20e Firmware No fix yet Fix from $1,6002025-05-01 MEDIUM 6.3 CVE-2025-44866 Tenda W20E V15.11.0.6 was found to contain a command injection vulnerability in the formSetDebugCfg function via the level parameter. This vulnerabil… W20e Firmware No fix yet Fix from $1,6002025-05-01 MEDIUM 6.3 CVE-2025-44867 Tenda W20E V15.11.0.6 was found to contain a command injection vulnerability in the formSetNetCheckTools function via the hostName parameter. This vu… W20e Firmware No fix yet Fix from $1,6002025-05-01 MEDIUM 6.5 CVE-2025-44860 TOTOLINK CA300-POE V6.2c.884_B20180522 was found to contain a command injection vulnerability in the msg_process function via the Port parameter. Thi… Ca300 Poe Firmware No fix yet Fix from $1,6002025-05-01 MEDIUM 6.3 CVE-2025-44861 TOTOLINK CA300-POE V6.2c.884_B20180522 was found to contain a command injection vulnerability in the CloudSrvUserdataVersionCheck function via the ur… Ca300 Poe Firmware No fix yet Fix from $1,6002025-05-01 MEDIUM 6.3 CVE-2025-44862 TOTOLINK CA300-POE V6.2c.884_B20180522 was found to contain a command injection vulnerability in the recvUpgradeNewFw function via the fwUrl paramete… Ca300 Poe Firmware No fix yet Fix from $1,6002025-05-01 MEDIUM 6.5 CVE-2025-44863 TOTOLINK CA300-POE V6.2c.884_B20180522 was found to contain a command injection vulnerability in the msg_process function via the Url parameter. This… Ca300 Poe Firmware No fix yet Fix from $1,6002025-05-01 MEDIUM 6.3 CVE-2025-44864 Tenda W20E V15.11.0.6 was found to contain a command injection vulnerability in the formSetDebugCfg function via the module parameter. This vulnerabi… W20e Firmware No fix yet Fix from $1,6002025-05-01 MEDIUM 6.3 CVE-2025-44847 TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the setWebWlanIdx function via the webWlanIdx param… Ca600 Poe Firmware No fix yet Fix from $1,6002025-05-01 MEDIUM 6.5 CVE-2025-44848 TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the msg_process function via the Url parameter. Thi… Ca600 Poe Firmware No fix yet Fix from $1,6002025-05-01 MEDIUM 6.5 CVE-2025-44839 TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the CloudSrvUserdataVersionCheck function via the m… Ca600 Poe Firmware No fix yet Fix from $1,6002025-05-01 MEDIUM 6.5 CVE-2025-44840 TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the CloudSrvUserdataVersionCheck function via the s… Ca600 Poe Firmware No fix yet Fix from $1,6002025-05-01 MEDIUM 6.5 CVE-2025-44841 TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the CloudSrvUserdataVersionCheck function via the v… Ca600 Poe Firmware No fix yet Fix from $1,6002025-05-01 MEDIUM 6.5 CVE-2025-44842 TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the msg_process function via the Port parameter. Th… Ca600 Poe Firmware No fix yet Fix from $1,6002025-05-01 MEDIUM 6.5 CVE-2025-44843 TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the CloudSrvUserdataVersionCheck function via the u… Ca600 Poe Firmware No fix yet Fix from $1,6002025-05-01 MEDIUM 6.5 CVE-2025-44844 TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the setUpgradeFW function via the FileName paramete… Ca600 Poe Firmware No fix yet Fix from $1,6002025-05-01 MEDIUM 6.5 CVE-2025-44845 TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the NTPSyncWithHost function via the hostTime param… Ca600 Poe Firmware No fix yet Fix from $1,6002025-05-01 MEDIUM 6.3 CVE-2025-44846 TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the recvUpgradeNewFw function via the fwUrl paramet… Ca600 Poe Firmware No fix yet Fix from $1,6002025-05-01 MEDIUM 6.3 CVE-2025-44836 TOTOLINK CPE CP900 V6.3c.1144_B20190715 was discovered to contain a command injection vulnerability in the setApRebootScheCfg function via the hour o… Cp900 Firmware No fix yet Fix from $1,6002025-05-01 MEDIUM 6.3 CVE-2025-44837 TOTOLINK CPE CP900 V6.3c.1144_B20190715 was discovered to contain a command injection vulnerability in the CloudSrvUserdataVersionCheck function via … Cp900 Firmware No fix yet Fix from $1,6002025-05-01 MEDIUM 6.3 CVE-2025-44838 TOTOLINK CPE CP900 V6.3c.1144_B20190715 was discovered to contain a command injection vulnerability in the setUploadUserData function via the FileNam… Cp900 Firmware No fix yet Fix from $1,6002025-05-01 MEDIUM 6.3 CVE-2025-44835 D-Link DIR-816 A2V1.1.0B05 was found to contain a command injection in iptablesWebsFilterRun, which allows remote attackers to execute arbitrary comm… Dir 816 A2 Firmware No fix yet Fix from $1,6002025-05-01 MEDIUM 6.3 CVE-2025-44854 TOTOLINK CP900 V6.3c.1144_B20190715 was found to contain a command injection vulnerability in the setUpgradeUboot function via the FileName parameter… Cp900 Firmware No fix yet Fix from $1,6002025-05-01