<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Command Injection</title>
  <link>https://cvedaily.com/pages/tags/command-injection.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/command-injection.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Command Injection</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:29 +0000</lastBuildDate>
  <item>
    <title>[Critical] CVE-2026-36576 – An OS command injection vulnerability in the app.py component of openlabs docker...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-36576</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-36576</guid>
    <pubDate>Wed, 03 Jun 2026 16:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-36576</strong></p>
  <p>An OS command injection vulnerability in the app.py component of openlabs docker-wkhtmltopdf-aas up to commit 9f50579 allows attackers to execute arbitrary commands via a crafted POST request.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-36576">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-10550 – A weakness has been identified in elunez eladmin up to 2.7. This vulnerability a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10550</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10550</guid>
    <pubDate>Tue, 02 Jun 2026 02:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-10550</strong></p>
  <p>A weakness has been identified in elunez eladmin up to 2.7. This vulnerability affects unknown code of the file App.java of the component Application Deployment Module. This manipulation of the argument uploadPath causes command injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. The project was informed of the…</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10550">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-10279 – A vulnerability was identified in hiraishikentaro wezterm-mcp 0.1.0. The affecte...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10279</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10279</guid>
    <pubDate>Mon, 01 Jun 2026 19:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-10279</strong></p>
  <p>A vulnerability was identified in hiraishikentaro wezterm-mcp 0.1.0. The affected element is an unknown function of the file src/wezterm_executor.ts of the component switch_pane/write_to_specific_pane. The manipulation of the argument request.params.arguments.pane_id leads to os command injection. The attack can be initiated remotely. The exploit is publicly available and might be used. The proje…</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10279">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10273 – A vulnerability was found in php-censor up to 2.1.6. This affects an unknown fun...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10273</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10273</guid>
    <pubDate>Mon, 01 Jun 2026 17:16:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10273</strong></p>
  <p>A vulnerability was found in php-censor up to 2.1.6. This affects an unknown function of the file src/Model/Build/GitBuild.php of the component Webhook Endpoint. Performing a manipulation of the argument commitId results in os command injection. The attack can be initiated remotely. The exploit has been made public and could be used. The patch is named cd68d102601320bd319d590b75f7652e66f0685f. It…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10273">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10219 – A vulnerability was found in nextlevelbuilder GoClaw up to 3.11.3. This impacts ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10219</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10219</guid>
    <pubDate>Mon, 01 Jun 2026 04:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10219</strong></p>
  <p>A vulnerability was found in nextlevelbuilder GoClaw up to 3.11.3. This impacts the function FsBridge.WriteFile of the file internal/sandbox/fsbridge.go of the component write_file Tool. Performing a manipulation results in os command injection. The attack is possible to be carried out remotely. The exploit has been made public and could be used. The pull request to fix this issue awaits acceptan…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10219">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10214 – A weakness has been identified in zhayujie chatgpt-on-wechat up to 2.0.8. This i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10214</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10214</guid>
    <pubDate>Mon, 01 Jun 2026 03:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10214</strong></p>
  <p>A weakness has been identified in zhayujie chatgpt-on-wechat up to 2.0.8. This issue affects the function _get_safety_warning of the file agent/tools/bash/bash.py of the component Bash Tool. Executing a manipulation can lead to os command injection. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks. Upgrading to version 2.0.9 is c…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10214">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-10182 – A vulnerability was determined in TRENDnet TEW-432BRP 3.10B20. The impacted elem...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10182</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10182</guid>
    <pubDate>Sun, 31 May 2026 14:16:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-10182</strong></p>
  <p>A vulnerability was determined in TRENDnet TEW-432BRP 3.10B20. The impacted element is the function formWlanSetup of the file /goform/formWlanSetup. Executing a manipulation of the argument enrollee can lead to command injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. The vendor explains: "This product has been EOL for 15 years (since 200…</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10182">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-10180 – A vulnerability has been found in TRENDnet TEW-432BRP 3.10B20. Impacted is the f...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10180</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10180</guid>
    <pubDate>Sun, 31 May 2026 12:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-10180</strong></p>
  <p>A vulnerability has been found in TRENDnet TEW-432BRP 3.10B20. Impacted is the function formSysCmd of the file /goform/formSysCmd. Such manipulation of the argument sysCmd leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor explains: "This product has been EOL for 15 years (since 2009). As the item has…</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10180">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-10166 – A vulnerability was determined in Edimax BR-6478AC 1.23. The affected element is...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10166</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10166</guid>
    <pubDate>Sun, 31 May 2026 04:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-10166</strong></p>
  <p>A vulnerability was determined in Edimax BR-6478AC 1.23. The affected element is the function formWlbasic of the file /goform/formWlbasic of the component POST Request Handler. This manipulation of the argument rootAPmac causes command injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized.</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10166">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-10127 – A weakness has been identified in Edimax BR-6478AC 1.23. This affects the functi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10127</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10127</guid>
    <pubDate>Sat, 30 May 2026 17:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-10127</strong></p>
  <p>A weakness has been identified in Edimax BR-6478AC 1.23. This affects the function formStaDrvSetup of the file /goform/formStaDrvSetup of the component POST Request Handler. This manipulation of the argument rootAPmac causes command injection. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks.</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10127">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-49366 – In JetBrains IntelliJ IDEA before 2026.1.1 command injection was possible via fi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-49366</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-49366</guid>
    <pubDate>Fri, 29 May 2026 19:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-49366</strong></p>
  <p>In JetBrains IntelliJ IDEA before 2026.1.1 command injection was possible via filename completion</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-49366">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-45633 – Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.6 and ear...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45633</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45633</guid>
    <pubDate>Fri, 29 May 2026 18:17:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-45633</strong></p>
  <p>Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.6 and earlier, Dokploy contains a command injection vulnerability in the /docker-container-logs WebSocket endpoint. The tail and since parameters are not validated and are directly concatenated into shell commands, allowing authenticated users to execute arbitrary commands with root privileges.</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45633">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-45630 – Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.28.8 and ear...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45630</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45630</guid>
    <pubDate>Fri, 29 May 2026 18:17:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-45630</strong></p>
  <p>Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.28.8 and earlier, authenticated OS command injection in the application.updateTraefikConfig tRPC endpoint allows admin/owner users to execute arbitrary system commands on remote servers via unsanitized echo shell interpolation.</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45630">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-45629 – Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.28.8 and ear...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45629</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45629</guid>
    <pubDate>Fri, 29 May 2026 18:17:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-45629</strong></p>
  <p>Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.28.8 and earlier, authenticated OS command injection in the /listen-deployment WebSocket endpoint allows any organization member to execute arbitrary system commands on remote servers managed by Dokploy, leading to full server compromise.</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45629">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-45663 – Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.1 and ear...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45663</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45663</guid>
    <pubDate>Fri, 29 May 2026 16:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-45663</strong></p>
  <p>Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.1 and earlier, a command injection vulnerability exists in the Docker file upload functionality. When an authenticated user uploads a file to a container, the destinationPath parameter is not properly sanitized and is directly interpolated into a shell command string. By including shell metacharacters such as ; or ", an attack…</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45663">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-45662 – Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.0 and ear...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45662</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45662</guid>
    <pubDate>Fri, 29 May 2026 16:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-45662</strong></p>
  <p>Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.0 and earlier, the deleteRegistry function in Dokploy (packages/server/src/services/registry.ts) executes docker logout ${response.registryUrl} without shell escaping. In the same file, the docker login command correctly uses shEscape() to prevent command injection. This inconsistency creates a command injection vulnerability…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45662">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-10061 – A vulnerability was found in TRENDnet TEW-432BRP 3.10B20. Affected is the functi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10061</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10061</guid>
    <pubDate>Fri, 29 May 2026 14:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-10061</strong></p>
  <p>A vulnerability was found in TRENDnet TEW-432BRP 3.10B20. Affected is the function formWPS of the file /goform/formWPS. The manipulation of the argument peerPin results in command injection. The attack can be executed remotely. The exploit has been made public and could be used. The vendor explains: "This product has been EOL for 15 years (since 2009). As the item has been EOL for such a long tim…</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10061">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-10060 – A vulnerability has been found in TRENDnet TEW-432BRP 3.10B20. This impacts the ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10060</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10060</guid>
    <pubDate>Fri, 29 May 2026 14:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-10060</strong></p>
  <p>A vulnerability has been found in TRENDnet TEW-432BRP 3.10B20. This impacts the function formSetRoute of the file /goform/formSetRoute. The manipulation of the argument ip/mask/gateway leads to command injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The vendor explains: "This product has been EOL for 15 years (since 2009). As…</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10060">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-41281 – Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Ele...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-41281</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-41281</guid>
    <pubDate>Fri, 29 May 2026 12:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-41281</strong></p>
  <p>Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in Waterfall WF-500 RX Host in version 7.9.1.0 R2502171040 that allows attackers with access to the TX Host to execute code on the RX Host when a MySQL connector is configured.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-41281">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-41279 – Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Ele...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-41279</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-41279</guid>
    <pubDate>Fri, 29 May 2026 12:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-41279</strong></p>
  <p>Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Administration WebUI in Waterfall WF-500 RX Host in version 7.9.1.0 R2502171040 that allows remote authenticated attackers to execute arbitrary operating system commands on the WF-500 RX Host.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-41279">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-41277 – Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Ele...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-41277</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-41277</guid>
    <pubDate>Fri, 29 May 2026 12:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-41277</strong></p>
  <p>Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to execute arbitrary operating system commands on the device.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-41277">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-41276 – Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Ele...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-41276</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-41276</guid>
    <pubDate>Fri, 29 May 2026 12:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-41276</strong></p>
  <p>Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to execute arbitrary operating system commands on the device.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-41276">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-41275 – Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Ele...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-41275</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-41275</guid>
    <pubDate>Fri, 29 May 2026 12:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-41275</strong></p>
  <p>Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to execute arbitrary operating system commands on the device.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-41275">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-41274 – Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Ele...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-41274</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-41274</guid>
    <pubDate>Fri, 29 May 2026 12:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-41274</strong></p>
  <p>Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to execute arbitrary operating system commands on the device.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-41274">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-41272 – Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Ele...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-41272</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-41272</guid>
    <pubDate>Fri, 29 May 2026 12:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-41272</strong></p>
  <p>Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to execute arbitrary operating system commands on the device.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-41272">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-41270 – Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Ele...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-41270</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-41270</guid>
    <pubDate>Fri, 29 May 2026 12:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-41270</strong></p>
  <p>Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to execute arbitrary operating system commands on the device.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-41270">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-41269 – Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Ele...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-41269</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-41269</guid>
    <pubDate>Fri, 29 May 2026 12:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-41269</strong></p>
  <p>Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to execute arbitrary operating system commands on the device.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-41269">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-41267 – Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Ele...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-41267</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-41267</guid>
    <pubDate>Fri, 29 May 2026 12:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-41267</strong></p>
  <p>Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Administration WebUI in Waterfall WF-500 TX Host in version 7.9.1.0 R2502171040 that allows remote authenticated attackers to execute arbitrary operating system commands on the WF-500 TX Host.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-41267">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-41266 – Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Ele...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-41266</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-41266</guid>
    <pubDate>Fri, 29 May 2026 12:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-41266</strong></p>
  <p>Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Administration WebUI in Waterfall WF-500 TX Host in version 7.9.1.0 R2502171040 that allows remote authenticated attackers to execute arbitrary operating system commands on the WF-500 TX Host.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-41266">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-41265 – Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Ele...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-41265</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-41265</guid>
    <pubDate>Fri, 29 May 2026 12:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-41265</strong></p>
  <p>Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Administration WebUI in Waterfall WF-500 TX Host in version 7.9.1.0 R2502171040 that allows remote authenticated attackers to execute arbitrary operating system commands on the WF-500 TX Host.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-41265">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-49199 – Crafted MQTT messages can trigger command injection, resulting in root-level cod...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-49199</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-49199</guid>
    <pubDate>Fri, 29 May 2026 09:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-49199</strong></p>
  <p>Crafted MQTT messages can trigger command injection, resulting in root-level code execution on the target device.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-49199">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-38707 – A command injection vulnerability exists in the IPSec VPN feature of InHand Netw...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-38707</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-38707</guid>
    <pubDate>Thu, 28 May 2026 17:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-38707</strong></p>
  <p>A command injection vulnerability exists in the IPSec VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmware V1.0.118, IR615 firmware V1.0.118, and earlier versions. Attackers can exploit this vulnerability to obtain ROOT privileges on remote target devices.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-38707">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-38704 – A command injection vulnerability exists in the WireGuard VPN feature of InHand ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-38704</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-38704</guid>
    <pubDate>Thu, 28 May 2026 17:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-38704</strong></p>
  <p>A command injection vulnerability exists in the WireGuard VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmware V1.0.118, IR615 firmware V1.0.118, and earlier versions. Attackers can exploit this vulnerability to obtain ROOT privileges on remote target devices.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-38704">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-38703 – A command injection vulnerability exists in the ZeroTier VPN feature of InHand N...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-38703</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-38703</guid>
    <pubDate>Thu, 28 May 2026 17:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-38703</strong></p>
  <p>A command injection vulnerability exists in the ZeroTier VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmware V1.0.118, IR615 firmware V1.0.118, and earlier versions. Attackers can exploit this vulnerability to obtain ROOT privileges on remote target devices.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-38703">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-38702 – A command injection vulnerability exists in the Admin Access feature of InHand N...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-38702</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-38702</guid>
    <pubDate>Thu, 28 May 2026 17:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-38702</strong></p>
  <p>A command injection vulnerability exists in the Admin Access feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmware V1.0.118, IR615 firmware V1.0.118, and earlier versions. Attackers can exploit this vulnerability to obtain ROOT privileges on remote target devices.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-38702">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44604 – A command injection vulnerability was discovered in the `rpmuncompress` utility ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44604</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44604</guid>
    <pubDate>Thu, 28 May 2026 08:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44604</strong></p>
  <p>A command injection vulnerability was discovered in the `rpmuncompress` utility of RPM. When extracting certain archive formats (ZIP, 7z, GEM) to a specified destination directory, the tool inserts the archive's top-level folder name into a shell command without properly sanitizing it. A specially crafted archive containing shell metacharacters in its folder name can execute arbitrary commands as…</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44604">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-45322 – Microsoft UFO open-source framework for intelligent automation across devices an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45322</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45322</guid>
    <pubDate>Wed, 27 May 2026 23:16:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-45322</strong></p>
  <p>Microsoft UFO open-source framework for intelligent automation across devices and platforms. Microsoft UFO tagged releases up to and including v3.0.0 contain an OS command injection vulnerability in the shell action replay path. In affected releases, ShellReceiver.run_shell() passes a command string from action parameters directly to subprocess.Popen() with shell=True and executable=powershell.ex…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45322">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-45152 – uniget is a universal installer and updater for (container) tools. Prior to 0.27...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45152</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45152</guid>
    <pubDate>Wed, 27 May 2026 22:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-45152</strong></p>
  <p>uniget is a universal installer and updater for (container) tools. Prior to 0.27.1, a command injection vulnerability exists in uniget due to unsafe execution of the check field from metadata files using /bin/bash -c. Because the check field is loaded directly from untrusted JSON metadata without validation or sanitization, an attacker can craft malicious metadata that executes arbitrary shell co…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45152">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44724 – systeminformation is a System and OS information library for node.js. From 4.17...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44724</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44724</guid>
    <pubDate>Wed, 27 May 2026 20:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44724</strong></p>
  <p>systeminformation is a System and OS information library for node.js. From 4.17.0 to 5.31.5, on Linux, systeminformation is vulnerable to command injection in networkInterfaces() when an active NetworkManager connection profile name contains shell metacharacters. The vulnerable value is obtained internally from real nmcli device status output. The library sanitizes the network interface name befo…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44724">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-44590 – Sherlock hunts down social media accounts by username across social networks. Pr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44590</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44590</guid>
    <pubDate>Wed, 27 May 2026 20:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-44590</strong></p>
  <p>Sherlock hunts down social media accounts by username across social networks. Prior to 0.16.1, the GitHub Actions workflow validate_modified_targets.yml is vulnerable to command injection via the pull_request_target trigger. Any GitHub user can execute arbitrary commands on the CI runner and exfiltrate the GITHUB_TOKEN by opening a pull request. No approval, review, or merge is required. This vul…</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44590">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-5509 – An authenticated command injection vulnerability exists in the Archer BE450 v1 a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5509</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5509</guid>
    <pubDate>Wed, 27 May 2026 18:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-5509</strong></p>
  <p>An authenticated command injection vulnerability exists in the Archer BE450 v1 and BE7200 v1 router that allows an administrator to execute arbitrary system commands through the web management interface. After successfully authenticating to the admin interface, an attacker can leverage the browser’s developer console by supplying a crafted input that is passed to backend system commands without a…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5509">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-69600 – Command injection in Raynet rvia RayVentory Scan Engine 12.6 Update 8 and previo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-69600</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-69600</guid>
    <pubDate>Wed, 27 May 2026 18:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-69600</strong></p>
  <p>Command injection in Raynet rvia RayVentory Scan Engine 12.6 Update 8 and previous versions allows adversaries to execute commands via getconfig, upload, inventory, and oracle options.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-69600">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-38945 – Command injection in Raynet rvia version 12.6 Update 8 and previous versions all...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-38945</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-38945</guid>
    <pubDate>Wed, 27 May 2026 17:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-38945</strong></p>
  <p>Command injection in Raynet rvia version 12.6 Update 8 and previous versions allows adversaries to execute arbitrary code via a crafted path that matches the improperly terminated search criteria of rvia's Java search using the find command.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-38945">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-36540 – Netis AC1200 Router NC21 V4.0.1.4296 is vulnerable to unauthenticated command in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-36540</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-36540</guid>
    <pubDate>Wed, 27 May 2026 14:16:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-36540</strong></p>
  <p>Netis AC1200 Router NC21 V4.0.1.4296 is vulnerable to unauthenticated command injection via the /cgi-bin/skk_set.cgi endpoint. The password and new_pwd_confirm POST parameters are passed directly to the underlying OS shell without sanitization. An attacker can inject arbitrary shell commands by wrapping them in backticks (`) and encoding them in base64. Because the endpoint requires no authentica…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-36540">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-36045 – picoclaw &lt;=v0.1.2 and earlier is vulnerable to OS command injection via the Exec...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-36045</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-36045</guid>
    <pubDate>Wed, 27 May 2026 14:16:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-36045</strong></p>
  <p>picoclaw <=v0.1.2 and earlier is vulnerable to OS command injection via the ExecTool component (pkg/tools/shell.go). The guardCommand() function attempts to restrict shell command execution using a denylist of 8 regular expressions, but the denylist is incomplete.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-36045">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-36044 – @pensar/apex &lt;= 0.0.58 is vulnerable to OS command injection via the smart_enume...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-36044</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-36044</guid>
    <pubDate>Wed, 27 May 2026 14:16:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-36044</strong></p>
  <p>@pensar/apex <= 0.0.58 is vulnerable to OS command injection via the smart_enumerate tool. The createSmartEnumerateTool() function in src/core/agent/tools.ts constructs a shell command by concatenating unsanitized values from the extensions array and url parameter into a string passed to Node.js child_process.exec(). Because exec() spawns a shell, shell metacharacters in those values are interpre…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-36044">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-8450 – HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_f...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8450</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8450</guid>
    <pubDate>Wed, 27 May 2026 05:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-8450</strong></p>
  <p>HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file().  send_file() opens its string argument with Perl's 2-arg open(). The 2-arg form interprets magic prefixes: '| cmd' and 'cmd |' open a pipe to a subprocess, '> path' and '>> path' open the path for write or append.  Untrusted input passed to send_file() can run OS commands at the daemon process UID. The read-pip…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-73</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8450">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-48695 – FastNetMon Community Edition through 1.2.9 contains an OS command injection vuln...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48695</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48695</guid>
    <pubDate>Tue, 26 May 2026 18:16:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-48695</strong></p>
  <p>FastNetMon Community Edition through 1.2.9 contains an OS command injection vulnerability in the MikroTik router integration plugin. The _log() function in src/mikrotik_plugin/fastnetmon_mikrotik.php (lines 107-108) constructs shell commands by concatenating the $msg parameter directly into exec() calls: exec("echo `date` \"- {FASTNETMON] - " . $msg . " \" >> " . $FILE_LOG_TMP). This is identical…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48695">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-9565 – A vulnerability was determined in haojing8312 WorkClaw up to 0.6.4. This affects...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9565</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9565</guid>
    <pubDate>Tue, 26 May 2026 17:16:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9565</strong></p>
  <p>A vulnerability was determined in haojing8312 WorkClaw up to 0.6.4. This affects the function is_dangerous of the file apps/runtime/src-tauri/src/agent/tools/bash.rs of the component Blacklist Handler. Executing a manipulation can lead to os command injection. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem…</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9565">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-48687 – FastNetMon Community Edition through 1.2.9 contains an OS command injection vuln...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48687</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48687</guid>
    <pubDate>Tue, 26 May 2026 16:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-48687</strong></p>
  <p>FastNetMon Community Edition through 1.2.9 contains an OS command injection vulnerability in the Juniper router integration plugin. The _log() function in src/juniper_plugin/fastnetmon_juniper.php (lines 117-118) constructs shell commands by concatenating the $msg parameter directly into exec() calls: exec("echo `date` \"- {FASTNETMON] - " . $msg . " \" >> " . $FILE_LOG_TMP). The $msg variable co…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48687">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46368 – luci-app-https-dns-proxy through 2025.12.29-5 — an optional LuCI web UI add-on f...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46368</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46368</guid>
    <pubDate>Tue, 26 May 2026 15:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46368</strong></p>
  <p>luci-app-https-dns-proxy through 2025.12.29-5 — an optional LuCI web UI add-on for the https-dns-proxy package, distributed through the OpenWrt community packages feed and not installed by default — contains a command injection vulnerability in the setInitAction function. An authenticated user holding the luci.https-dns-proxy ACL permission can inject shell metacharacters through the 'name' param…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46368">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-9543 – A vulnerability has been found in Totolink N300RH 6.1c.1353_B20190305. Affected ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9543</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9543</guid>
    <pubDate>Tue, 26 May 2026 14:16:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-9543</strong></p>
  <p>A vulnerability has been found in Totolink N300RH 6.1c.1353_B20190305. Affected is the function setPasswordCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Such manipulation of the argument admpass leads to os command injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9543">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-9534 – A flaw has been found in Totolink CA750-PoE 6.2c.510. This affects the function ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9534</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9534</guid>
    <pubDate>Tue, 26 May 2026 07:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9534</strong></p>
  <p>A flaw has been found in Totolink CA750-PoE 6.2c.510. This affects the function setWiFiWpsConfig of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. Executing a manipulation of the argument PIN can lead to os command injection. It is possible to launch the attack remotely. The exploit has been published and may be used.</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9534">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-9533 – A vulnerability was detected in Totolink CA750-PoE 6.2c.510. The impacted elemen...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9533</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9533</guid>
    <pubDate>Tue, 26 May 2026 07:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9533</strong></p>
  <p>A vulnerability was detected in Totolink CA750-PoE 6.2c.510. The impacted element is the function recvUpgradeNewFw of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. Performing a manipulation of the argument fwUrl/magicid results in os command injection. It is possible to initiate the attack remotely. The exploit is now public and may be used.</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9533">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-9532 – A security vulnerability has been detected in Totolink CA750-PoE 6.2c.510. The a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9532</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9532</guid>
    <pubDate>Tue, 26 May 2026 07:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9532</strong></p>
  <p>A security vulnerability has been detected in Totolink CA750-PoE 6.2c.510. The affected element is the function setUploadUserData of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. Such manipulation of the argument FileName leads to os command injection. The attack may be performed from remote. The exploit has been disclosed publicly and may be used.</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9532">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-9531 – A weakness has been identified in Totolink CA750-PoE 6.2c.510. Impacted is the f...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9531</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9531</guid>
    <pubDate>Tue, 26 May 2026 05:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9531</strong></p>
  <p>A weakness has been identified in Totolink CA750-PoE 6.2c.510. Impacted is the function setUpgradeUboot of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. This manipulation of the argument FileName causes os command injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks.</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9531">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-9515 – A vulnerability was detected in Totolink CA750-PoE 6.2c.510. The affected elemen...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9515</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9515</guid>
    <pubDate>Tue, 26 May 2026 00:16:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9515</strong></p>
  <p>A vulnerability was detected in Totolink CA750-PoE 6.2c.510. The affected element is the function setUnloadUserData of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. The manipulation of the argument plugin_version results in os command injection. The attack may be launched remotely. The exploit is now public and may be used.</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9515">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-9514 – A security vulnerability has been detected in Totolink CA750-PoE 6.2c.510. Impac...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9514</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9514</guid>
    <pubDate>Mon, 25 May 2026 23:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9514</strong></p>
  <p>A security vulnerability has been detected in Totolink CA750-PoE 6.2c.510. Impacted is the function setNetworkDiag of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. The manipulation of the argument NetDiagHost/NetDiagPingNum/NetDiagPingSize/NetDiagPingTimeOut/NetDiagTracertHop is directly passed by the attacker/so we can control the NetDiagHost/NetDiagPingNum/NetDiagPingSize/NetD…</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9514">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-9513 – A weakness has been identified in Totolink CA750-PoE 6.2c.510. This issue affect...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9513</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9513</guid>
    <pubDate>Mon, 25 May 2026 23:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9513</strong></p>
  <p>A weakness has been identified in Totolink CA750-PoE 6.2c.510. This issue affects the function NTPSyncWithHost of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. Executing a manipulation of the argument host_time can lead to os command injection. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks.</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9513">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-9512 – A security flaw has been discovered in Totolink CA750-PoE 6.2c.510. This vulnera...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9512</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9512</guid>
    <pubDate>Mon, 25 May 2026 23:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9512</strong></p>
  <p>A security flaw has been discovered in Totolink CA750-PoE 6.2c.510. This vulnerability affects the function setPasswordCfg of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. Performing a manipulation of the argument admuser/admpass results in os command injection. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks.</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9512">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-9511 – A vulnerability was identified in Totolink CA750-PoE 6.2c.510. This affects the ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9511</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9511</guid>
    <pubDate>Mon, 25 May 2026 22:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9511</strong></p>
  <p>A vulnerability was identified in Totolink CA750-PoE 6.2c.510. This affects the function setWebWlanIdx of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. Such manipulation of the argument webWlanIdx leads to os command injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used.</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9511">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-9478 – A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. Impacted...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9478</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9478</guid>
    <pubDate>Mon, 25 May 2026 18:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-9478</strong></p>
  <p>A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the function setParentalRules of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Executing a manipulation of the argument enable can lead to os command injection. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9478">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-9477 – A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. Thi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9477</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9477</guid>
    <pubDate>Mon, 25 May 2026 18:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-9477</strong></p>
  <p>A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setAccessDeviceCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Performing a manipulation of the argument mac results in os command injection. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for a…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9477">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-9476 – A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. This vul...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9476</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9476</guid>
    <pubDate>Mon, 25 May 2026 17:16:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-9476</strong></p>
  <p>A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects the function setPasswordCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Such manipulation of the argument admpass leads to os command injection. The attack can be executed remotely. The exploit is publicly available and might be used.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9476">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-9475 – A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. This aff...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9475</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9475</guid>
    <pubDate>Mon, 25 May 2026 17:16:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-9475</strong></p>
  <p>A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. This affects the function setIpQosRules of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. This manipulation of the argument Comment causes os command injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9475">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-9458 – A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. The impa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9458</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9458</guid>
    <pubDate>Mon, 25 May 2026 14:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-9458</strong></p>
  <p>A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. The impacted element is the function setWanCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Such manipulation of the argument enabled leads to os command injection. The attack may be performed from remote. The exploit is publicly available and might be used.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9458">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-9457 – A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. The affe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9457</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9457</guid>
    <pubDate>Mon, 25 May 2026 14:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-9457</strong></p>
  <p>A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. The affected element is the function UploadFirmwareFile of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. This manipulation of the argument FileName causes os command injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9457">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-9456 – A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. Impacted is t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9456</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9456</guid>
    <pubDate>Mon, 25 May 2026 13:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-9456</strong></p>
  <p>A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the function setOpenVpnCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. The manipulation of the argument enabled results in os command injection. The attack can be executed remotely. The exploit has been made public and could be used.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9456">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-9455 – A vulnerability has been found in Totolink A8000RU 7.1cu.643_b20200521. This iss...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9455</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9455</guid>
    <pubDate>Mon, 25 May 2026 13:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-9455</strong></p>
  <p>A vulnerability has been found in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function UploadOpenVpnCert of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. The manipulation of the argument FileName leads to os command injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9455">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-9454 – A flaw has been found in Totolink A8000RU 7.1cu.643_b20200521. This vulnerabilit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9454</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9454</guid>
    <pubDate>Mon, 25 May 2026 13:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-9454</strong></p>
  <p>A flaw has been found in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects the function setOpenVpnCertGenerationCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Executing a manipulation of the argument servername can lead to os command injection. The attack may be launched remotely. The exploit has been published and may be used.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9454">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9453 – A vulnerability was detected in FoundDream miniclawd up to 2d65665046e2222eeea76...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9453</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9453</guid>
    <pubDate>Mon, 25 May 2026 13:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9453</strong></p>
  <p>A vulnerability was detected in FoundDream miniclawd up to 2d65665046e2222eeea76cafc8570ed546a8c125. This affects the function which of the file /src/application/skills-loader.ts of the component SkillsLoader. Performing a manipulation of the argument requires.bins results in command injection. The attack may be initiated remotely. The exploit is now public and may be used. This product uses a ro…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9453">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9452 – A security vulnerability has been detected in FoundDream miniclawd up to 2d65665...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9452</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9452</guid>
    <pubDate>Mon, 25 May 2026 11:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9452</strong></p>
  <p>A security vulnerability has been detected in FoundDream miniclawd up to 2d65665046e2222eeea76cafc8570ed546a8c125. Affected by this issue is the function ExecTool.execute of the file /src/tools/exec.ts. Such manipulation leads to os command injection. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. This product does not use versioning. This is why inf…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9452">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-9441 – A security flaw has been discovered in Edimax BR-6478AC 1.23. Affected by this i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9441</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9441</guid>
    <pubDate>Mon, 25 May 2026 10:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9441</strong></p>
  <p>A security flaw has been discovered in Edimax BR-6478AC 1.23. Affected by this issue is the function formiNICbasic of the file /goform/formiNICbasic of the component POST Request Handler. Performing a manipulation of the argument rootAPmac results in command injection. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was con…</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9441">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-9440 – A vulnerability was identified in Edimax BR-6478AC 1.23. Affected by this vulner...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9440</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9440</guid>
    <pubDate>Mon, 25 May 2026 08:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9440</strong></p>
  <p>A vulnerability was identified in Edimax BR-6478AC 1.23. Affected by this vulnerability is the function formAccept of the file /goform/formAccept of the component POST Request Handler. Such manipulation of the argument submit-url leads to command injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this…</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9440">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-9439 – A vulnerability was determined in Edimax BR-6675nD 1.12. Affected is the functio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9439</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9439</guid>
    <pubDate>Mon, 25 May 2026 08:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9439</strong></p>
  <p>A vulnerability was determined in Edimax BR-6675nD 1.12. Affected is the function stainfo of the file /goform/stainfo. This manipulation of the argument interface causes command injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9439">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-9437 – A vulnerability has been found in DTStack Taier 1.4.0. This affects the function...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9437</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9437</guid>
    <pubDate>Mon, 25 May 2026 08:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9437</strong></p>
  <p>A vulnerability has been found in DTStack Taier 1.4.0. This affects the function Runtime.exec of the component REST API. The manipulation of the argument sqlText leads to os command injection. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9437">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-9436 – A flaw has been found in Totolink A8000RU 7.1cu.643_b20200521. The impacted elem...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9436</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9436</guid>
    <pubDate>Mon, 25 May 2026 08:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-9436</strong></p>
  <p>A flaw has been found in Totolink A8000RU 7.1cu.643_b20200521. The impacted element is the function setL2tpServerCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Executing a manipulation of the argument enable can lead to os command injection. The attack can be executed remotely. The exploit has been published and may be used.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9436">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-9435 – A vulnerability was detected in Totolink A8000RU 7.1cu.643_b20200521. The affect...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9435</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9435</guid>
    <pubDate>Mon, 25 May 2026 08:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-9435</strong></p>
  <p>A vulnerability was detected in Totolink A8000RU 7.1cu.643_b20200521. The affected element is the function setQosCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Performing a manipulation of the argument enable results in os command injection. Remote exploitation of the attack is possible. The exploit is now public and may be used.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9435">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-9434 – A security vulnerability has been detected in Totolink A8000RU 7.1cu.643_b202005...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9434</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9434</guid>
    <pubDate>Mon, 25 May 2026 07:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-9434</strong></p>
  <p>A security vulnerability has been detected in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the function setWiFiWpsCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Such manipulation of the argument wscDisabled leads to os command injection. The attack may be launched remotely. The exploit has been disclosed publicly and may be used.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9434">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-9433 – A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. This iss...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9433</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9433</guid>
    <pubDate>Mon, 25 May 2026 07:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-9433</strong></p>
  <p>A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setMacFilterRules of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. This manipulation of the argument enable causes os command injection. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9433">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-9432 – A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. Thi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9432</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9432</guid>
    <pubDate>Mon, 25 May 2026 07:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-9432</strong></p>
  <p>A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects the function setWiFiAdvancedCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. The manipulation of the argument bgProtection results in os command injection. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9432">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-9424 – A weakness has been identified in Edimax EW-7438RPn 1.31. The affected element i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9424</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9424</guid>
    <pubDate>Mon, 25 May 2026 05:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9424</strong></p>
  <p>A weakness has been identified in Edimax EW-7438RPn 1.31. The affected element is the function formWlanMP of the file /goform/formWlanMP of the component Content-Type Handler. Executing a manipulation of the argument ateFunc/ateGain/ateTxCount/ateChan/ateRate/ateMacID/e2pTxPower1/e2pTxPower2/e2pTxPower3/e2pTxPower4/e2pTxPower5/e2pTxPower6/e2pTxPower7/e2pTx2Power1/e2pTx2Power2/e2pTx2Power3/e2pTx2P…</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9424">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-9423 – A security flaw has been discovered in Edimax BR-6675nD 1.12. Impacted is the fu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9423</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9423</guid>
    <pubDate>Mon, 25 May 2026 05:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9423</strong></p>
  <p>A security flaw has been discovered in Edimax BR-6675nD 1.12. Impacted is the function mp of the file /goform/mp of the component POST Request Handler. Performing a manipulation of the argument command results in command injection. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but…</p>
  <p><strong>CVSS:</strong> 4.7 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9423">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8652 – An OS Command Injection vulnerability exists in Aterm. If a malicious third pers...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8652</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8652</guid>
    <pubDate>Mon, 25 May 2026 04:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8652</strong></p>
  <p>An OS Command Injection vulnerability exists in Aterm. If a malicious third person gains administrator access to the product’s web console, they may be able to execute arbitrary OS commands via adjacent network.</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8652">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-9408 – A vulnerability was detected in Totolink A8000RU 7.1cu.643_b20200521. Affected b...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9408</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9408</guid>
    <pubDate>Mon, 25 May 2026 00:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-9408</strong></p>
  <p>A vulnerability was detected in Totolink A8000RU 7.1cu.643_b20200521. Affected by this issue is the function setStaticDhcpRules of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. The manipulation of the argument enable results in os command injection. The attack may be performed from remote. The exploit is now public and may be used.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9408">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-9407 – A security vulnerability has been detected in Totolink A8000RU 7.1cu.643_b202005...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9407</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9407</guid>
    <pubDate>Mon, 25 May 2026 00:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-9407</strong></p>
  <p>A security vulnerability has been detected in Totolink A8000RU 7.1cu.643_b20200521. Affected by this vulnerability is the function setFirewallType of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. The manipulation of the argument firewallType leads to os command injection. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9407">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-9406 – A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. Affected...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9406</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9406</guid>
    <pubDate>Mon, 25 May 2026 00:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-9406</strong></p>
  <p>A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. Affected is the function setRemoteCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Executing a manipulation of the argument enable can lead to os command injection. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9406">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-9405 – A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. Thi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9405</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9405</guid>
    <pubDate>Mon, 25 May 2026 00:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-9405</strong></p>
  <p>A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. This impacts the function setGameSpeedCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Performing a manipulation of the argument enable results in os command injection. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9405">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-9404 – A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. This aff...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9404</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9404</guid>
    <pubDate>Sun, 24 May 2026 23:16:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-9404</strong></p>
  <p>A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. This affects the function setDdnsCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Such manipulation of the argument provider leads to os command injection. The attack may be launched remotely. The exploit is publicly available and might be used.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9404">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-9402 – A vulnerability was found in Edimax BR-6675nD 1.12. The affected element is the ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9402</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9402</guid>
    <pubDate>Sun, 24 May 2026 23:16:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9402</strong></p>
  <p>A vulnerability was found in Edimax BR-6675nD 1.12. The affected element is the function formWlanMP of the file /goform/formWlanMP of the component POST Request Handler. The manipulation of the argument ateFunc/ateGain/ateRate/ateChan/ateTxCount/e2pTx2Power1/e2pTx2Power2/e2pTx2Power3/e2pTx2Power4/e2pTx2Power5/e2pTx2Power6/e2pTx2Power7/e2pTxPower1/e2pTxPower2/e2pTxPower3/e2pTxPower4/e2pTxPower5/e2…</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9402">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-9400 – A flaw has been found in Edimax BR-6675nD 1.12. This issue affects the function ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9400</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9400</guid>
    <pubDate>Sun, 24 May 2026 23:16:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9400</strong></p>
  <p>A flaw has been found in Edimax BR-6675nD 1.12. This issue affects the function formUSBStorage of the file /goform/formUSBStorage of the component POST Request Handler. Executing a manipulation of the argument sub_dir can lead to command injection. It is possible to launch the attack remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but…</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9400">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-9388 – A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. The impa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9388</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9388</guid>
    <pubDate>Sun, 24 May 2026 15:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-9388</strong></p>
  <p>A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. The impacted element is the function setScheduleCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Executing a manipulation of the argument mode can lead to os command injection. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for a…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9388">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-9387 – A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. The...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9387</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9387</guid>
    <pubDate>Sun, 24 May 2026 15:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-9387</strong></p>
  <p>A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. The affected element is the function setUpgradeFW of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Performing a manipulation of the argument resetFlags results in os command injection. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used fo…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9387">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-9386 – A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. Impacted...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9386</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9386</guid>
    <pubDate>Sun, 24 May 2026 15:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-9386</strong></p>
  <p>A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the function setLanguageCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Such manipulation of the argument lang leads to os command injection. The attack may be performed from remote. The exploit is publicly available and might be used.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9386">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-9385 – A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. This iss...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9385</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9385</guid>
    <pubDate>Sun, 24 May 2026 14:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-9385</strong></p>
  <p>A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setTracerouteCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. This manipulation of the argument command causes os command injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9385">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-9384 – A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. This vulnerab...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9384</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9384</guid>
    <pubDate>Sun, 24 May 2026 14:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-9384</strong></p>
  <p>A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects the function setDiagnosisCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. The manipulation of the argument ip results in os command injection. The attack can be executed remotely. The exploit has been made public and could be used.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9384">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-9379 – A weakness has been identified in Edimax BR-6675nD 1.12. This impacts the functi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9379</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9379</guid>
    <pubDate>Sun, 24 May 2026 12:16:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9379</strong></p>
  <p>A weakness has been identified in Edimax BR-6675nD 1.12. This impacts the function formWpsStart of the file /goform/formWpsStart of the component POST Request Handler. This manipulation of the argument pinCode causes command injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this di…</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9379">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-9378 – A security flaw has been discovered in Edimax BR-6675nD 1.12. This affects the f...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9378</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9378</guid>
    <pubDate>Sun, 24 May 2026 12:16:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9378</strong></p>
  <p>A security flaw has been discovered in Edimax BR-6675nD 1.12. This affects the function formHwSet of the file /goform/formHwSet of the component POST Request Handler. The manipulation of the argument regDomain/ABandregDomain/nic0Addr/nic1Addr/wlanAddr/inicAddr results in command injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be used fo…</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9378">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9367 – A vulnerability was determined in NousResearch hermes-agent up to 5157f5427f1948...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9367</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9367</guid>
    <pubDate>Sun, 24 May 2026 09:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9367</strong></p>
  <p>A vulnerability was determined in NousResearch hermes-agent up to 5157f5427f19488b31c6fdebbacd15d798ce7f63. This affects the function detect_dangerous_command of the file tools/approval.py of the component terminal_tool. This manipulation causes os command injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contact…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9367">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-9363 – A vulnerability was detected in Edimax EW-7438RPn 1.12. This issue affects the f...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9363</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9363</guid>
    <pubDate>Sun, 24 May 2026 08:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9363</strong></p>
  <p>A vulnerability was detected in Edimax EW-7438RPn 1.12. This issue affects the function formEZCHNwlanSetup of the file /goform/formEZCHNwlanSetu of the component POST Request Handler. Performing a manipulation of the argument method results in command injection. Remote exploitation of the attack is possible. The exploit is now public and may be used. The vendor was contacted early about this disc…</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9363">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
