Topic
Command Injection
14 reports tagged Command Injection, spanning vulnerability coverage.
Articles tagged Command Injection
-
VulnerabilityD-Link DIR-882 Vulnerability (CVE-2025-60698)
CVE-2025-60698 is a CVSS 7.3 unauthenticated command injection in D-Link DIR-882 router firmware, per VulnCheck alone.
-
VulnerabilityKopia Command Injection (CVE-2026-45695)
CVE-2026-45695 is a CVSS 9.8 OS command injection flaw enabling unauthenticated RCE in the Kopia backup tool before 0.23.0, reported exploited by VulnCheck KEV.
-
VulnerabilityShenzhen Aitemi E Commerce Co., Ltd. Command Injection (CVE-2026-58457)
CVE-2026-58457 is a CVSS 9.8 unauthenticated command injection flaw in the Shenzhen Aitemi M300 Wi-Fi repeater, reported exploited by VulnCheck.
-
VulnerabilityTelesquare TLR-2005KSH Vulnerability (CVE-2025-9603)
CVE-2025-9603 is a CVSS 6.3 command injection in Telesquare TLR-2005KSH router firmware, publicly exploited per VulnCheck.
-
VulnerabilityTenda CH22 Vulnerability (CVE-2026-78141)
CVE-2026-78141 is a CVSS 7.4 command injection in the Tenda CH22 router firmware, with a public exploit per NVD.
-
VulnerabilityTenda CH22 Vulnerability (CVE-2026-5153)
CVE-2026-5153 is a CVSS 6.3 command injection in Tenda CH22 router firmware, publicly exploited per VulnCheck.
-
VulnerabilityTOTOLINK A7000R Vulnerability (CVE-2026-1547)
CVE-2026-1547 is a CVSS 6.3 command injection in TOTOLINK A7000R router firmware, publicly exploited per VulnCheck.
-
VulnerabilityTOTOLINK A950RG Vulnerability (CVE-2025-60702)
CVE-2025-60702 is a CVSS 6.5 unauthenticated command injection in TOTOLINK A950RG router firmware, per VulnCheck alone.
-
VulnerabilityTOTOLINK LR1200GB Vulnerability (CVE-2025-60687)
CVE-2025-60687 is a CVSS 6.5 unauthenticated command injection in TOTOLINK LR1200GB router firmware, per VulnCheck alone.
-
Vulnerability2 CVEs Across 3 Vendors (CVE-2026-74233)
CVE-2026-74233 and CVE-2026-74232 are two CVSS 9.8 unauthenticated RCE flaws in Zbtlink router firmware, reported exploited by VulnCheck KEV.
-
VulnerabilityZimbra Collaboration Suite Command Injection (CVE-2026-73570)
CVE-2026-73570 is a CVSS 8.9 OS command injection in Zimbra Collaboration Suite via SNMP notification handling, confirmed exploited per CISA KEV.
-
VulnerabilityKestra OSS Authentication Bypass (CVE-2026-49869)
CVE-2026-49869 is a CVSS 10.0 authentication-filter bypass in Kestra OSS, KEV-listed Sept. 2, 2026 as exploited. NVD reports fixes in 1.0.45 and 1.3.21.
-
Vulnerability2 SonicWall SMA1000 Appliances CVEs (CVE-2026-83548)
CVE-2026-83548 is a CVSS 10.0 pre-auth SSRF in SonicWall SMA1000 appliances, KEV-listed Sept. 2, 2026 beside CVE-2026-83549, a post-auth command injection.
-
VulnerabilityLinksys RE7000 2.0.15 Command Injection (CVE-2026-86299)
CVE-2026-86299 is a CVSS 9.9 critical OS command injection in Linksys RE7000 firmware, reachable remotely via the PingTest handler, with public exploit code available.