<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Command Injection (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/command-injection.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/command-injection-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Command Injection (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:29 +0000</lastBuildDate>
  <item>
    <title>[Critical] CVE-2026-36576 – An OS command injection vulnerability in the app.py component of openlabs docker...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-36576</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-36576</guid>
    <pubDate>Wed, 03 Jun 2026 16:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-36576</strong></p>
  <p>An OS command injection vulnerability in the app.py component of openlabs docker-wkhtmltopdf-aas up to commit 9f50579 allows attackers to execute arbitrary commands via a crafted POST request.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-36576">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10273 – A vulnerability was found in php-censor up to 2.1.6. This affects an unknown fun...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10273</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10273</guid>
    <pubDate>Mon, 01 Jun 2026 17:16:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10273</strong></p>
  <p>A vulnerability was found in php-censor up to 2.1.6. This affects an unknown function of the file src/Model/Build/GitBuild.php of the component Webhook Endpoint. Performing a manipulation of the argument commitId results in os command injection. The attack can be initiated remotely. The exploit has been made public and could be used. The patch is named cd68d102601320bd319d590b75f7652e66f0685f. It…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10273">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10219 – A vulnerability was found in nextlevelbuilder GoClaw up to 3.11.3. This impacts ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10219</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10219</guid>
    <pubDate>Mon, 01 Jun 2026 04:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10219</strong></p>
  <p>A vulnerability was found in nextlevelbuilder GoClaw up to 3.11.3. This impacts the function FsBridge.WriteFile of the file internal/sandbox/fsbridge.go of the component write_file Tool. Performing a manipulation results in os command injection. The attack is possible to be carried out remotely. The exploit has been made public and could be used. The pull request to fix this issue awaits acceptan…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10219">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10214 – A weakness has been identified in zhayujie chatgpt-on-wechat up to 2.0.8. This i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10214</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10214</guid>
    <pubDate>Mon, 01 Jun 2026 03:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10214</strong></p>
  <p>A weakness has been identified in zhayujie chatgpt-on-wechat up to 2.0.8. This issue affects the function _get_safety_warning of the file agent/tools/bash/bash.py of the component Bash Tool. Executing a manipulation can lead to os command injection. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks. Upgrading to version 2.0.9 is c…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10214">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-49366 – In JetBrains IntelliJ IDEA before 2026.1.1 command injection was possible via fi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-49366</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-49366</guid>
    <pubDate>Fri, 29 May 2026 19:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-49366</strong></p>
  <p>In JetBrains IntelliJ IDEA before 2026.1.1 command injection was possible via filename completion</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-49366">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-45633 – Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.6 and ear...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45633</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45633</guid>
    <pubDate>Fri, 29 May 2026 18:17:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-45633</strong></p>
  <p>Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.6 and earlier, Dokploy contains a command injection vulnerability in the /docker-container-logs WebSocket endpoint. The tail and since parameters are not validated and are directly concatenated into shell commands, allowing authenticated users to execute arbitrary commands with root privileges.</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45633">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-45630 – Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.28.8 and ear...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45630</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45630</guid>
    <pubDate>Fri, 29 May 2026 18:17:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-45630</strong></p>
  <p>Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.28.8 and earlier, authenticated OS command injection in the application.updateTraefikConfig tRPC endpoint allows admin/owner users to execute arbitrary system commands on remote servers via unsanitized echo shell interpolation.</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45630">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-45629 – Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.28.8 and ear...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45629</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45629</guid>
    <pubDate>Fri, 29 May 2026 18:17:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-45629</strong></p>
  <p>Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.28.8 and earlier, authenticated OS command injection in the /listen-deployment WebSocket endpoint allows any organization member to execute arbitrary system commands on remote servers managed by Dokploy, leading to full server compromise.</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45629">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-45663 – Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.1 and ear...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45663</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45663</guid>
    <pubDate>Fri, 29 May 2026 16:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-45663</strong></p>
  <p>Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.1 and earlier, a command injection vulnerability exists in the Docker file upload functionality. When an authenticated user uploads a file to a container, the destinationPath parameter is not properly sanitized and is directly interpolated into a shell command string. By including shell metacharacters such as ; or ", an attack…</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45663">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-45662 – Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.0 and ear...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45662</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45662</guid>
    <pubDate>Fri, 29 May 2026 16:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-45662</strong></p>
  <p>Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.0 and earlier, the deleteRegistry function in Dokploy (packages/server/src/services/registry.ts) executes docker logout ${response.registryUrl} without shell escaping. In the same file, the docker login command correctly uses shEscape() to prevent command injection. This inconsistency creates a command injection vulnerability…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45662">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-41281 – Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Ele...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-41281</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-41281</guid>
    <pubDate>Fri, 29 May 2026 12:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-41281</strong></p>
  <p>Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in Waterfall WF-500 RX Host in version 7.9.1.0 R2502171040 that allows attackers with access to the TX Host to execute code on the RX Host when a MySQL connector is configured.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-41281">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-41279 – Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Ele...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-41279</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-41279</guid>
    <pubDate>Fri, 29 May 2026 12:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-41279</strong></p>
  <p>Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Administration WebUI in Waterfall WF-500 RX Host in version 7.9.1.0 R2502171040 that allows remote authenticated attackers to execute arbitrary operating system commands on the WF-500 RX Host.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-41279">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-41277 – Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Ele...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-41277</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-41277</guid>
    <pubDate>Fri, 29 May 2026 12:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-41277</strong></p>
  <p>Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to execute arbitrary operating system commands on the device.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-41277">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-41276 – Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Ele...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-41276</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-41276</guid>
    <pubDate>Fri, 29 May 2026 12:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-41276</strong></p>
  <p>Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to execute arbitrary operating system commands on the device.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-41276">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-41275 – Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Ele...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-41275</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-41275</guid>
    <pubDate>Fri, 29 May 2026 12:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-41275</strong></p>
  <p>Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to execute arbitrary operating system commands on the device.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-41275">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-41274 – Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Ele...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-41274</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-41274</guid>
    <pubDate>Fri, 29 May 2026 12:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-41274</strong></p>
  <p>Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to execute arbitrary operating system commands on the device.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-41274">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-41272 – Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Ele...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-41272</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-41272</guid>
    <pubDate>Fri, 29 May 2026 12:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-41272</strong></p>
  <p>Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to execute arbitrary operating system commands on the device.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-41272">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-41270 – Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Ele...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-41270</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-41270</guid>
    <pubDate>Fri, 29 May 2026 12:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-41270</strong></p>
  <p>Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to execute arbitrary operating system commands on the device.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-41270">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-41269 – Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Ele...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-41269</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-41269</guid>
    <pubDate>Fri, 29 May 2026 12:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-41269</strong></p>
  <p>Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to execute arbitrary operating system commands on the device.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-41269">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-41267 – Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Ele...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-41267</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-41267</guid>
    <pubDate>Fri, 29 May 2026 12:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-41267</strong></p>
  <p>Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Administration WebUI in Waterfall WF-500 TX Host in version 7.9.1.0 R2502171040 that allows remote authenticated attackers to execute arbitrary operating system commands on the WF-500 TX Host.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-41267">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-41266 – Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Ele...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-41266</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-41266</guid>
    <pubDate>Fri, 29 May 2026 12:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-41266</strong></p>
  <p>Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Administration WebUI in Waterfall WF-500 TX Host in version 7.9.1.0 R2502171040 that allows remote authenticated attackers to execute arbitrary operating system commands on the WF-500 TX Host.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-41266">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-41265 – Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Ele...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-41265</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-41265</guid>
    <pubDate>Fri, 29 May 2026 12:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-41265</strong></p>
  <p>Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Administration WebUI in Waterfall WF-500 TX Host in version 7.9.1.0 R2502171040 that allows remote authenticated attackers to execute arbitrary operating system commands on the WF-500 TX Host.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-41265">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-49199 – Crafted MQTT messages can trigger command injection, resulting in root-level cod...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-49199</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-49199</guid>
    <pubDate>Fri, 29 May 2026 09:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-49199</strong></p>
  <p>Crafted MQTT messages can trigger command injection, resulting in root-level code execution on the target device.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-49199">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-38707 – A command injection vulnerability exists in the IPSec VPN feature of InHand Netw...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-38707</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-38707</guid>
    <pubDate>Thu, 28 May 2026 17:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-38707</strong></p>
  <p>A command injection vulnerability exists in the IPSec VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmware V1.0.118, IR615 firmware V1.0.118, and earlier versions. Attackers can exploit this vulnerability to obtain ROOT privileges on remote target devices.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-38707">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-38704 – A command injection vulnerability exists in the WireGuard VPN feature of InHand ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-38704</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-38704</guid>
    <pubDate>Thu, 28 May 2026 17:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-38704</strong></p>
  <p>A command injection vulnerability exists in the WireGuard VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmware V1.0.118, IR615 firmware V1.0.118, and earlier versions. Attackers can exploit this vulnerability to obtain ROOT privileges on remote target devices.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-38704">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-38703 – A command injection vulnerability exists in the ZeroTier VPN feature of InHand N...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-38703</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-38703</guid>
    <pubDate>Thu, 28 May 2026 17:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-38703</strong></p>
  <p>A command injection vulnerability exists in the ZeroTier VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmware V1.0.118, IR615 firmware V1.0.118, and earlier versions. Attackers can exploit this vulnerability to obtain ROOT privileges on remote target devices.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-38703">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-38702 – A command injection vulnerability exists in the Admin Access feature of InHand N...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-38702</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-38702</guid>
    <pubDate>Thu, 28 May 2026 17:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-38702</strong></p>
  <p>A command injection vulnerability exists in the Admin Access feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmware V1.0.118, IR615 firmware V1.0.118, and earlier versions. Attackers can exploit this vulnerability to obtain ROOT privileges on remote target devices.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-38702">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44604 – A command injection vulnerability was discovered in the `rpmuncompress` utility ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44604</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44604</guid>
    <pubDate>Thu, 28 May 2026 08:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44604</strong></p>
  <p>A command injection vulnerability was discovered in the `rpmuncompress` utility of RPM. When extracting certain archive formats (ZIP, 7z, GEM) to a specified destination directory, the tool inserts the archive's top-level folder name into a shell command without properly sanitizing it. A specially crafted archive containing shell metacharacters in its folder name can execute arbitrary commands as…</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44604">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-45322 – Microsoft UFO open-source framework for intelligent automation across devices an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45322</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45322</guid>
    <pubDate>Wed, 27 May 2026 23:16:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-45322</strong></p>
  <p>Microsoft UFO open-source framework for intelligent automation across devices and platforms. Microsoft UFO tagged releases up to and including v3.0.0 contain an OS command injection vulnerability in the shell action replay path. In affected releases, ShellReceiver.run_shell() passes a command string from action parameters directly to subprocess.Popen() with shell=True and executable=powershell.ex…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45322">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-45152 – uniget is a universal installer and updater for (container) tools. Prior to 0.27...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45152</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45152</guid>
    <pubDate>Wed, 27 May 2026 22:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-45152</strong></p>
  <p>uniget is a universal installer and updater for (container) tools. Prior to 0.27.1, a command injection vulnerability exists in uniget due to unsafe execution of the check field from metadata files using /bin/bash -c. Because the check field is loaded directly from untrusted JSON metadata without validation or sanitization, an attacker can craft malicious metadata that executes arbitrary shell co…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45152">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44724 – systeminformation is a System and OS information library for node.js. From 4.17...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44724</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44724</guid>
    <pubDate>Wed, 27 May 2026 20:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44724</strong></p>
  <p>systeminformation is a System and OS information library for node.js. From 4.17.0 to 5.31.5, on Linux, systeminformation is vulnerable to command injection in networkInterfaces() when an active NetworkManager connection profile name contains shell metacharacters. The vulnerable value is obtained internally from real nmcli device status output. The library sanitizes the network interface name befo…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44724">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-44590 – Sherlock hunts down social media accounts by username across social networks. Pr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44590</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44590</guid>
    <pubDate>Wed, 27 May 2026 20:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-44590</strong></p>
  <p>Sherlock hunts down social media accounts by username across social networks. Prior to 0.16.1, the GitHub Actions workflow validate_modified_targets.yml is vulnerable to command injection via the pull_request_target trigger. Any GitHub user can execute arbitrary commands on the CI runner and exfiltrate the GITHUB_TOKEN by opening a pull request. No approval, review, or merge is required. This vul…</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44590">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-5509 – An authenticated command injection vulnerability exists in the Archer BE450 v1 a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5509</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5509</guid>
    <pubDate>Wed, 27 May 2026 18:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-5509</strong></p>
  <p>An authenticated command injection vulnerability exists in the Archer BE450 v1 and BE7200 v1 router that allows an administrator to execute arbitrary system commands through the web management interface. After successfully authenticating to the admin interface, an attacker can leverage the browser’s developer console by supplying a crafted input that is passed to backend system commands without a…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5509">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-69600 – Command injection in Raynet rvia RayVentory Scan Engine 12.6 Update 8 and previo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-69600</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-69600</guid>
    <pubDate>Wed, 27 May 2026 18:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-69600</strong></p>
  <p>Command injection in Raynet rvia RayVentory Scan Engine 12.6 Update 8 and previous versions allows adversaries to execute commands via getconfig, upload, inventory, and oracle options.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-69600">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-38945 – Command injection in Raynet rvia version 12.6 Update 8 and previous versions all...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-38945</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-38945</guid>
    <pubDate>Wed, 27 May 2026 17:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-38945</strong></p>
  <p>Command injection in Raynet rvia version 12.6 Update 8 and previous versions allows adversaries to execute arbitrary code via a crafted path that matches the improperly terminated search criteria of rvia's Java search using the find command.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-38945">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-36540 – Netis AC1200 Router NC21 V4.0.1.4296 is vulnerable to unauthenticated command in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-36540</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-36540</guid>
    <pubDate>Wed, 27 May 2026 14:16:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-36540</strong></p>
  <p>Netis AC1200 Router NC21 V4.0.1.4296 is vulnerable to unauthenticated command injection via the /cgi-bin/skk_set.cgi endpoint. The password and new_pwd_confirm POST parameters are passed directly to the underlying OS shell without sanitization. An attacker can inject arbitrary shell commands by wrapping them in backticks (`) and encoding them in base64. Because the endpoint requires no authentica…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-36540">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-36045 – picoclaw &lt;=v0.1.2 and earlier is vulnerable to OS command injection via the Exec...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-36045</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-36045</guid>
    <pubDate>Wed, 27 May 2026 14:16:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-36045</strong></p>
  <p>picoclaw <=v0.1.2 and earlier is vulnerable to OS command injection via the ExecTool component (pkg/tools/shell.go). The guardCommand() function attempts to restrict shell command execution using a denylist of 8 regular expressions, but the denylist is incomplete.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-36045">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-36044 – @pensar/apex &lt;= 0.0.58 is vulnerable to OS command injection via the smart_enume...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-36044</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-36044</guid>
    <pubDate>Wed, 27 May 2026 14:16:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-36044</strong></p>
  <p>@pensar/apex <= 0.0.58 is vulnerable to OS command injection via the smart_enumerate tool. The createSmartEnumerateTool() function in src/core/agent/tools.ts constructs a shell command by concatenating unsanitized values from the extensions array and url parameter into a string passed to Node.js child_process.exec(). Because exec() spawns a shell, shell metacharacters in those values are interpre…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-36044">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-8450 – HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_f...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8450</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8450</guid>
    <pubDate>Wed, 27 May 2026 05:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-8450</strong></p>
  <p>HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file().  send_file() opens its string argument with Perl's 2-arg open(). The 2-arg form interprets magic prefixes: '| cmd' and 'cmd |' open a pipe to a subprocess, '> path' and '>> path' open the path for write or append.  Untrusted input passed to send_file() can run OS commands at the daemon process UID. The read-pip…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-73</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8450">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-48695 – FastNetMon Community Edition through 1.2.9 contains an OS command injection vuln...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48695</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48695</guid>
    <pubDate>Tue, 26 May 2026 18:16:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-48695</strong></p>
  <p>FastNetMon Community Edition through 1.2.9 contains an OS command injection vulnerability in the MikroTik router integration plugin. The _log() function in src/mikrotik_plugin/fastnetmon_mikrotik.php (lines 107-108) constructs shell commands by concatenating the $msg parameter directly into exec() calls: exec("echo `date` \"- {FASTNETMON] - " . $msg . " \" >> " . $FILE_LOG_TMP). This is identical…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48695">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-48687 – FastNetMon Community Edition through 1.2.9 contains an OS command injection vuln...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48687</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48687</guid>
    <pubDate>Tue, 26 May 2026 16:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-48687</strong></p>
  <p>FastNetMon Community Edition through 1.2.9 contains an OS command injection vulnerability in the Juniper router integration plugin. The _log() function in src/juniper_plugin/fastnetmon_juniper.php (lines 117-118) constructs shell commands by concatenating the $msg parameter directly into exec() calls: exec("echo `date` \"- {FASTNETMON] - " . $msg . " \" >> " . $FILE_LOG_TMP). The $msg variable co…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48687">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46368 – luci-app-https-dns-proxy through 2025.12.29-5 — an optional LuCI web UI add-on f...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46368</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46368</guid>
    <pubDate>Tue, 26 May 2026 15:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46368</strong></p>
  <p>luci-app-https-dns-proxy through 2025.12.29-5 — an optional LuCI web UI add-on for the https-dns-proxy package, distributed through the OpenWrt community packages feed and not installed by default — contains a command injection vulnerability in the setInitAction function. An authenticated user holding the luci.https-dns-proxy ACL permission can inject shell metacharacters through the 'name' param…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46368">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-9543 – A vulnerability has been found in Totolink N300RH 6.1c.1353_B20190305. Affected ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9543</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9543</guid>
    <pubDate>Tue, 26 May 2026 14:16:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-9543</strong></p>
  <p>A vulnerability has been found in Totolink N300RH 6.1c.1353_B20190305. Affected is the function setPasswordCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Such manipulation of the argument admpass leads to os command injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9543">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-9478 – A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. Impacted...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9478</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9478</guid>
    <pubDate>Mon, 25 May 2026 18:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-9478</strong></p>
  <p>A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the function setParentalRules of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Executing a manipulation of the argument enable can lead to os command injection. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9478">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-9477 – A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. Thi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9477</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9477</guid>
    <pubDate>Mon, 25 May 2026 18:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-9477</strong></p>
  <p>A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setAccessDeviceCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Performing a manipulation of the argument mac results in os command injection. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for a…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9477">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-9476 – A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. This vul...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9476</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9476</guid>
    <pubDate>Mon, 25 May 2026 17:16:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-9476</strong></p>
  <p>A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects the function setPasswordCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Such manipulation of the argument admpass leads to os command injection. The attack can be executed remotely. The exploit is publicly available and might be used.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9476">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-9475 – A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. This aff...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9475</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9475</guid>
    <pubDate>Mon, 25 May 2026 17:16:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-9475</strong></p>
  <p>A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. This affects the function setIpQosRules of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. This manipulation of the argument Comment causes os command injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9475">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-9458 – A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. The impa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9458</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9458</guid>
    <pubDate>Mon, 25 May 2026 14:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-9458</strong></p>
  <p>A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. The impacted element is the function setWanCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Such manipulation of the argument enabled leads to os command injection. The attack may be performed from remote. The exploit is publicly available and might be used.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9458">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-9457 – A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. The affe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9457</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9457</guid>
    <pubDate>Mon, 25 May 2026 14:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-9457</strong></p>
  <p>A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. The affected element is the function UploadFirmwareFile of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. This manipulation of the argument FileName causes os command injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9457">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-9456 – A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. Impacted is t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9456</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9456</guid>
    <pubDate>Mon, 25 May 2026 13:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-9456</strong></p>
  <p>A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the function setOpenVpnCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. The manipulation of the argument enabled results in os command injection. The attack can be executed remotely. The exploit has been made public and could be used.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9456">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-9455 – A vulnerability has been found in Totolink A8000RU 7.1cu.643_b20200521. This iss...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9455</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9455</guid>
    <pubDate>Mon, 25 May 2026 13:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-9455</strong></p>
  <p>A vulnerability has been found in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function UploadOpenVpnCert of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. The manipulation of the argument FileName leads to os command injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9455">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-9454 – A flaw has been found in Totolink A8000RU 7.1cu.643_b20200521. This vulnerabilit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9454</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9454</guid>
    <pubDate>Mon, 25 May 2026 13:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-9454</strong></p>
  <p>A flaw has been found in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects the function setOpenVpnCertGenerationCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Executing a manipulation of the argument servername can lead to os command injection. The attack may be launched remotely. The exploit has been published and may be used.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9454">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9453 – A vulnerability was detected in FoundDream miniclawd up to 2d65665046e2222eeea76...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9453</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9453</guid>
    <pubDate>Mon, 25 May 2026 13:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9453</strong></p>
  <p>A vulnerability was detected in FoundDream miniclawd up to 2d65665046e2222eeea76cafc8570ed546a8c125. This affects the function which of the file /src/application/skills-loader.ts of the component SkillsLoader. Performing a manipulation of the argument requires.bins results in command injection. The attack may be initiated remotely. The exploit is now public and may be used. This product uses a ro…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9453">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9452 – A security vulnerability has been detected in FoundDream miniclawd up to 2d65665...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9452</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9452</guid>
    <pubDate>Mon, 25 May 2026 11:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9452</strong></p>
  <p>A security vulnerability has been detected in FoundDream miniclawd up to 2d65665046e2222eeea76cafc8570ed546a8c125. Affected by this issue is the function ExecTool.execute of the file /src/tools/exec.ts. Such manipulation leads to os command injection. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. This product does not use versioning. This is why inf…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9452">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-9436 – A flaw has been found in Totolink A8000RU 7.1cu.643_b20200521. The impacted elem...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9436</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9436</guid>
    <pubDate>Mon, 25 May 2026 08:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-9436</strong></p>
  <p>A flaw has been found in Totolink A8000RU 7.1cu.643_b20200521. The impacted element is the function setL2tpServerCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Executing a manipulation of the argument enable can lead to os command injection. The attack can be executed remotely. The exploit has been published and may be used.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9436">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-9435 – A vulnerability was detected in Totolink A8000RU 7.1cu.643_b20200521. The affect...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9435</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9435</guid>
    <pubDate>Mon, 25 May 2026 08:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-9435</strong></p>
  <p>A vulnerability was detected in Totolink A8000RU 7.1cu.643_b20200521. The affected element is the function setQosCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Performing a manipulation of the argument enable results in os command injection. Remote exploitation of the attack is possible. The exploit is now public and may be used.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9435">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-9434 – A security vulnerability has been detected in Totolink A8000RU 7.1cu.643_b202005...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9434</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9434</guid>
    <pubDate>Mon, 25 May 2026 07:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-9434</strong></p>
  <p>A security vulnerability has been detected in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the function setWiFiWpsCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Such manipulation of the argument wscDisabled leads to os command injection. The attack may be launched remotely. The exploit has been disclosed publicly and may be used.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9434">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-9433 – A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. This iss...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9433</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9433</guid>
    <pubDate>Mon, 25 May 2026 07:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-9433</strong></p>
  <p>A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setMacFilterRules of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. This manipulation of the argument enable causes os command injection. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9433">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-9432 – A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. Thi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9432</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9432</guid>
    <pubDate>Mon, 25 May 2026 07:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-9432</strong></p>
  <p>A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects the function setWiFiAdvancedCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. The manipulation of the argument bgProtection results in os command injection. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9432">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8652 – An OS Command Injection vulnerability exists in Aterm. If a malicious third pers...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8652</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8652</guid>
    <pubDate>Mon, 25 May 2026 04:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8652</strong></p>
  <p>An OS Command Injection vulnerability exists in Aterm. If a malicious third person gains administrator access to the product’s web console, they may be able to execute arbitrary OS commands via adjacent network.</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8652">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-9408 – A vulnerability was detected in Totolink A8000RU 7.1cu.643_b20200521. Affected b...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9408</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9408</guid>
    <pubDate>Mon, 25 May 2026 00:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-9408</strong></p>
  <p>A vulnerability was detected in Totolink A8000RU 7.1cu.643_b20200521. Affected by this issue is the function setStaticDhcpRules of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. The manipulation of the argument enable results in os command injection. The attack may be performed from remote. The exploit is now public and may be used.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9408">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-9407 – A security vulnerability has been detected in Totolink A8000RU 7.1cu.643_b202005...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9407</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9407</guid>
    <pubDate>Mon, 25 May 2026 00:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-9407</strong></p>
  <p>A security vulnerability has been detected in Totolink A8000RU 7.1cu.643_b20200521. Affected by this vulnerability is the function setFirewallType of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. The manipulation of the argument firewallType leads to os command injection. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9407">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-9406 – A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. Affected...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9406</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9406</guid>
    <pubDate>Mon, 25 May 2026 00:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-9406</strong></p>
  <p>A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. Affected is the function setRemoteCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Executing a manipulation of the argument enable can lead to os command injection. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9406">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-9405 – A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. Thi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9405</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9405</guid>
    <pubDate>Mon, 25 May 2026 00:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-9405</strong></p>
  <p>A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. This impacts the function setGameSpeedCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Performing a manipulation of the argument enable results in os command injection. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9405">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-9404 – A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. This aff...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9404</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9404</guid>
    <pubDate>Sun, 24 May 2026 23:16:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-9404</strong></p>
  <p>A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. This affects the function setDdnsCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Such manipulation of the argument provider leads to os command injection. The attack may be launched remotely. The exploit is publicly available and might be used.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9404">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-9388 – A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. The impa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9388</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9388</guid>
    <pubDate>Sun, 24 May 2026 15:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-9388</strong></p>
  <p>A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. The impacted element is the function setScheduleCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Executing a manipulation of the argument mode can lead to os command injection. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for a…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9388">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-9387 – A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. The...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9387</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9387</guid>
    <pubDate>Sun, 24 May 2026 15:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-9387</strong></p>
  <p>A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. The affected element is the function setUpgradeFW of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Performing a manipulation of the argument resetFlags results in os command injection. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used fo…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9387">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-9386 – A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. Impacted...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9386</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9386</guid>
    <pubDate>Sun, 24 May 2026 15:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-9386</strong></p>
  <p>A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the function setLanguageCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Such manipulation of the argument lang leads to os command injection. The attack may be performed from remote. The exploit is publicly available and might be used.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9386">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-9385 – A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. This iss...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9385</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9385</guid>
    <pubDate>Sun, 24 May 2026 14:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-9385</strong></p>
  <p>A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setTracerouteCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. This manipulation of the argument command causes os command injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9385">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-9384 – A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. This vulnerab...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9384</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9384</guid>
    <pubDate>Sun, 24 May 2026 14:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-9384</strong></p>
  <p>A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects the function setDiagnosisCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. The manipulation of the argument ip results in os command injection. The attack can be executed remotely. The exploit has been made public and could be used.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9384">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9367 – A vulnerability was determined in NousResearch hermes-agent up to 5157f5427f1948...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9367</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9367</guid>
    <pubDate>Sun, 24 May 2026 09:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9367</strong></p>
  <p>A vulnerability was determined in NousResearch hermes-agent up to 5157f5427f19488b31c6fdebbacd15d798ce7f63. This affects the function detect_dangerous_command of the file tools/approval.py of the component terminal_tool. This manipulation causes os command injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contact…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9367">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-41090 – Improper neutralization of special elements used in a command ('command injectio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41090</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41090</guid>
    <pubDate>Fri, 22 May 2026 23:16:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-41090</strong></p>
  <p>Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to perform tampering over a network.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41090">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-23652 – Improper neutralization of special elements used in a command ('command injectio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-23652</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-23652</guid>
    <pubDate>Fri, 22 May 2026 23:16:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-23652</strong></p>
  <p>Improper neutralization of special elements used in a command ('command injection') in Microsoft Power Pages allows an unauthorized attacker to execute code over a network.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-23652">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-34910 – A malicious actor with access to the network could exploit an Improper Input Val...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34910</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34910</guid>
    <pubDate>Fri, 22 May 2026 02:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-34910</strong></p>
  <p>A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command Injection.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34910">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-33000 – A malicious actor with access to the network and high privileges could exploit a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33000</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33000</guid>
    <pubDate>Fri, 22 May 2026 02:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-33000</strong></p>
  <p>A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command Injection.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33000">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-5433 – Honeywell Control
Network Module (CNM) contains command injection vulnerability
...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5433</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5433</guid>
    <pubDate>Thu, 21 May 2026 09:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-5433</strong></p>
  <p>Honeywell Control Network Module (CNM) contains command injection vulnerability in the web interface. An attacker could exploit this vulnerability via command delimiters, potentially resulting in Remote Code Execution (RCE).</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5433">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8632 – A potential security vulnerability has been identified in the HP Linux Imaging a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8632</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8632</guid>
    <pubDate>Wed, 20 May 2026 21:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8632</strong></p>
  <p>A potential security vulnerability has been identified in the HP Linux Imaging and Printing Software. This potential vulnerability may allow escalation of privileges and/or arbitrary code execution via operating system command injection.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8632">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-8603 – In ScadaBR version 1.2.0, an OS Command Injection vulnerability could allow an a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8603</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8603</guid>
    <pubDate>Tue, 19 May 2026 18:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-8603</strong></p>
  <p>In ScadaBR version 1.2.0, an OS Command Injection vulnerability could allow an attacker to execute commands as root on the SCADA system.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8603">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-36828 – A command injection vulnerability exists in the /cgi-bin/tools/ajax_cmd endpoint...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-36828</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-36828</guid>
    <pubDate>Tue, 19 May 2026 17:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-36828</strong></p>
  <p>A command injection vulnerability exists in the /cgi-bin/tools/ajax_cmd endpoint of Panabit PAP-XM320 up to and including v7.7. The CGI component allows authenticated users to execute arbitrary shell commands with root privileges via the action=runcmd parameter.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-36828">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-37281 – An OS command injection vulnerability in the /stream-to-vlc Express route in hit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-37281</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-37281</guid>
    <pubDate>Tue, 19 May 2026 16:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-37281</strong></p>
  <p>An OS command injection vulnerability in the /stream-to-vlc Express route in hitarth-gg Zenshin before 2.7.0 allows remote attackers to execute arbitrary commands via the url parameter.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-37281">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-27130 – Dokploy is a free, self-hostable Platform as a Service (PaaS). Versions 0.26.6 a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27130</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27130</guid>
    <pubDate>Mon, 18 May 2026 21:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-27130</strong></p>
  <p>Dokploy is a free, self-hostable Platform as a Service (PaaS). Versions 0.26.6 and below have OS command injection through the appName parameter. 3 chained issues cause this problem: inadequate input sanitization, lack of schema validation and direct shell interpolation. User-controlled application names are passed through inadequate sanitization (cleanAppName function only replaces spaces and co…</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27130">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-25244 – WebdriverIO is a test automation framework for unit, e2e and component testing u...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-25244</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25244</guid>
    <pubDate>Mon, 18 May 2026 21:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-25244</strong></p>
  <p>WebdriverIO is a test automation framework for unit, e2e and component testing using WebDriver, WebDriver BiDi and Appium. Versions below 9.24.0 contain a command injection vulnerability leading to remote code execution (RCE) in test orchestration. Git permits branch names containing shell metacharacters, and getGitMetadataForAISelection() interpolates these names directly into execSync() calls w…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25244">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-47092 – Claude HUD through 0.0.12, patched in commit 234d9aa, contains a command injecti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-47092</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-47092</guid>
    <pubDate>Mon, 18 May 2026 20:16:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-47092</strong></p>
  <p>Claude HUD through 0.0.12, patched in commit 234d9aa, contains a command injection vulnerability that allows local attackers to execute arbitrary commands by manipulating the COMSPEC environment variable. Attackers can set COMSPEC to an arbitrary binary path before claude-hud performs its version check, causing execFile() to execute the attacker-supplied executable with cmd.exe arguments, resulti…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-427</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-47092">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-57282 – ngrok v4.3.3 and 5.0.0-beta.2 is vulnerable to Command Injection.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-57282</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-57282</guid>
    <pubDate>Mon, 18 May 2026 16:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-57282</strong></p>
  <p>ngrok v4.3.3 and 5.0.0-beta.2 is vulnerable to Command Injection.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-57282">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-39054 – Oinone Pamirs 7.0.0 contains a command injection vulnerability in CommandHelper...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39054</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39054</guid>
    <pubDate>Fri, 15 May 2026 15:16:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-39054</strong></p>
  <p>Oinone Pamirs 7.0.0 contains a command injection vulnerability in CommandHelper.executeCommands. The method starts a shell process and writes attacker-controlled command strings directly to the process standard input without sanitization. In affected deployments, this can result in arbitrary operating system command execution.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39054">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-24712 – Northern.tech CFEngine Enterprise and Community before 3.21.8, 3.24.3, and 3.27...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24712</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24712</guid>
    <pubDate>Thu, 14 May 2026 15:16:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-24712</strong></p>
  <p>Northern.tech CFEngine Enterprise and Community before 3.21.8, 3.24.3, and 3.27.0 allows Command injection.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24712">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-8500 – Web::Passwd versions through 0.03 for Perl is vulnerable to RCE.

Web::Passwd is...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8500</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8500</guid>
    <pubDate>Wed, 13 May 2026 23:16:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-8500</strong></p>
  <p>Web::Passwd versions through 0.03 for Perl is vulnerable to RCE.  Web::Passwd is a small CGI application for managing htpasswd files using the htpasswd command.  The user parameter is not validated or escaped, and is used as the last argument on the command line, allowing for command injection.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8500">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-36741 – U-SPEED AC1200 Gigabit Wi-Fi Router (Model: T18-21K) V1.0 is vulnerable to Comma...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-36741</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-36741</guid>
    <pubDate>Wed, 13 May 2026 16:16:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-36741</strong></p>
  <p>U-SPEED AC1200 Gigabit Wi-Fi Router (Model: T18-21K) V1.0 is vulnerable to Command Injection. The Network Time Protocol (NTP) configuration interface does not properly sanitize user-supplied input. An authenticated user with permission to configure NTP settings can inject arbitrary system commands through crafted input fields. These commands are executed with elevated privileges, leading to poten…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-36741">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-34176 – When running in Appliance mode, an authenticated remote command injection vulner...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34176</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34176</guid>
    <pubDate>Wed, 13 May 2026 16:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-34176</strong></p>
  <p>When running in Appliance mode, an authenticated remote command injection vulnerability exists in an undisclosed iControl REST endpoint. A successful exploit can allow the attacker to cross a security boundary.    Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34176">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-42062 – ELECOM wireless LAN access point devices contain an OS command injection in proc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42062</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42062</guid>
    <pubDate>Wed, 13 May 2026 13:16:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-42062</strong></p>
  <p>ELECOM wireless LAN access point devices contain an OS command injection in processing of username parameter. If processing a crafted request, an arbitrary OS command may be executed. No authentication is required.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42062">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-35506 – ELECOM wireless LAN access point devices contain an OS command injection vulnera...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-35506</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-35506</guid>
    <pubDate>Wed, 13 May 2026 13:16:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-35506</strong></p>
  <p>ELECOM wireless LAN access point devices contain an OS command injection vulnerability in processing of ping_ip_addr parameter. If processing a crafted request sent by a logged-in user, an arbitrary OS command may be executed.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35506">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44871 – Command injection vulnerabilities exist in the command line interface (CLI) serv...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44871</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44871</guid>
    <pubDate>Tue, 12 May 2026 22:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44871</strong></p>
  <p>Command injection vulnerabilities exist in the command line interface (CLI) service accessed by the PAPI protocol of AOS-8 and AOS-10 Operating Systems. Successful exploitation of these vulnerabilities could allow an authenticated remote attacker to execute arbitrary commands on the underlying operating system.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44871">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44872 – A command injection vulnerability exists in the web-based management interface o...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44872</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44872</guid>
    <pubDate>Tue, 12 May 2026 20:16:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44872</strong></p>
  <p>A command injection vulnerability exists in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful exploitation could allow an authenticated remote attacker to place arbitrary files on the underlying filesystem of the affected device.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44872">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44870 – Command injection vulnerabilities exist in the command line interface (CLI) serv...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44870</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44870</guid>
    <pubDate>Tue, 12 May 2026 20:16:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44870</strong></p>
  <p>Command injection vulnerabilities exist in the command line interface (CLI) service accessed by the PAPI protocol of AOS-8 and AOS-10 Operating Systems. Successful exploitation of these vulnerabilities could allow an authenticated remote attacker to execute arbitrary commands on the underlying operating system.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44870">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44869 – Command injection vulnerabilities exist in the web-based management interface of...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44869</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44869</guid>
    <pubDate>Tue, 12 May 2026 20:16:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44869</strong></p>
  <p>Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful exploitation of these vulnerabilities could allow an authenticated remote attacker to execute arbitrary commands on the underlying operating system.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44869">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44868 – Command injection vulnerabilities exist in the web-based management interface of...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44868</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44868</guid>
    <pubDate>Tue, 12 May 2026 20:16:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44868</strong></p>
  <p>Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful exploitation of these vulnerabilities could allow an authenticated remote attacker to execute arbitrary commands on the underlying operating system.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44868">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44867 – Command injection vulnerabilities exist in the web-based management interface of...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44867</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44867</guid>
    <pubDate>Tue, 12 May 2026 20:16:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44867</strong></p>
  <p>Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful exploitation of these vulnerabilities could allow an authenticated remote attacker to execute arbitrary commands on the underlying operating system.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44867">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44866 – Command injection vulnerabilities exist in the web-based management interface of...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44866</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44866</guid>
    <pubDate>Tue, 12 May 2026 20:16:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44866</strong></p>
  <p>Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful exploitation of these vulnerabilities could allow an authenticated remote attacker to execute arbitrary commands on the underlying operating system.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44866">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44865 – Command injection vulnerabilities exist in the web-based management interface of...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44865</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44865</guid>
    <pubDate>Tue, 12 May 2026 20:16:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44865</strong></p>
  <p>Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful exploitation of these vulnerabilities could allow an authenticated remote attacker to execute arbitrary commands on the underlying operating system.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44865">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44854 – Command injection vulnerabilities exist in the web-based management interface of...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44854</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44854</guid>
    <pubDate>Tue, 12 May 2026 20:16:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44854</strong></p>
  <p>Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful exploitation could allow an authenticated remote attacker to upload arbitrary files to the underlying operating system, potentially leading to remote code execution as a privileged user.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44854">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
