Total
6725 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-58147 | 2026-09-16 | N/A | N/A | ||
| WNC T-Mobile 5G Box IDU router contains an OS command injection vulnerability in the portal.cgi component's password change functionality. The application improperly neutralizes special elements in the http_passwd_hidden and http_passwdConfirm_hidden parameters, allowing an authenticated attacker to execute arbitrary commands on the underlying operating system with root privileges.This issue has been fixed in firmware version 1.1.0.651412 | |||||
| CVE-2026-58146 | 2026-09-16 | N/A | N/A | ||
| WNC T-Mobile 5G Box IDU router is vulnerable to OS command injection vulnerability. The vulnerability exists within the /cgi-bin/portal.cgi endpoint, specifically through the cli_cookie POST parameter. The cli_cookie parameter value is directly concatenated into a find command string without proper sanitization. This allows a remote, unauthenticated attacker to inject and execute arbitrary shell commands as root on the underlying operating system. This issue has been fixed in firmware version 1.1.0.651412 | |||||
| CVE-2026-40855 | 2026-09-16 | N/A | N/A | ||
| WNC T-Mobile 5G Box IDU router is vulnerable to a command injection. The vulnerability exists in the ping functionality within the /cgi-bin/portal.cgi endpoint, specifically affecting the ping_ip, ping_size, and ping_times POST parameters. The root cause is the failure to verify and sanitize user-supplied input before incorporating it into a system command. This allows an authenticated attacker to execute arbitrary commands on the shell and gain root access to the system.This issue has been fixed in firmware version 1.1.0.651412 | |||||
| CVE-2026-85979 | 2026-09-16 | N/A | N/A | ||
| Affected versions of Puppet Enterprise contain a command injection vulnerability. An authenticated user with Puppet administrative privileges can inject arbitrary shell commands by providing a specially crafted value for this parameter, which is passed to a shell execution context without sufficient sanitization. Because the resulting commands are executed with root privileges, successful exploitation can lead to full compromise of the affected system. It affects Puppet Enterprise 2023.8.0 through 2023.8.10 and Puppet Enterprise 2025.0.0 through 2025.11.2. This has been resolved in Puppet Enterprise 2023.8.11 and Puppet Enterprise 2025.11.3. | |||||
| CVE-2026-27565 | 2026-09-16 | N/A | 9.8 CRITICAL | ||
| An unauthenticated remote attacker can upload a malicious IODD file that places and executes a shell script with root privileges. The shell script remains active even after a reboot. | |||||
| CVE-2026-27564 | 2026-09-16 | N/A | 7.2 HIGH | ||
| A high-privileged remote attacker can exploit a command injection vulnerability in the /api/datastorage/data endpoint by sending a PUT request with admin credentials allowing execution of commands with root privileges on the device. | |||||
| CVE-2026-27563 | 2026-09-16 | N/A | 7.2 HIGH | ||
| A high-privileged remote attacker can exploit a command injection vulnerability in the /api/datastorage/data endpoint by sending a crafted GET request with admin credentials allowing execution of commands with root privileges on the device. | |||||
| CVE-2026-27562 | 2026-09-16 | N/A | 7.2 HIGH | ||
| A high-privileged remote attacker can exploit a command injection vulnerability in the /api/iodd/config endpoint by sending a crafted PUT request with admin credentials allowing execution of commands with root privileges on the device. | |||||
| CVE-2026-27561 | 2026-09-16 | N/A | 7.2 HIGH | ||
| A high-privileged remote attacker can exploit a command injection vulnerability in the /api/iodd/config endpoint by sending a crafted GET request with admin credentials allowing execution of commands with root privileges on the device. | |||||
| CVE-2026-27560 | 2026-09-16 | N/A | 7.2 HIGH | ||
| A high-privileged remote attacker can exploit a command injection vulnerability in the /api/status/data endpoint by sending a crafted DELETE request with admin credentials allowing execution of commands with root privileges on the device. | |||||
| CVE-2026-27559 | 2026-09-16 | N/A | 8.8 HIGH | ||
| A low-privileged remote attacker can exploit a command injection vulnerability in the /api/status/data endpoint by sending a crafted GET request with user credentials allowing execution of commands with root privileges on the device. | |||||
| CVE-2026-27558 | 2026-09-16 | N/A | 8.8 HIGH | ||
| A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/attached_devices_tab/ajax_remove_uploaded_iodd_files endpoint using operator credentials allowing execution of commands with root privileges on the device. | |||||
| CVE-2026-27554 | 2026-09-16 | N/A | 8.8 HIGH | ||
| A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/save_iodd_parameters endpoint using operator credentials allowing execution of commands with root privileges on the device. | |||||
| CVE-2026-27551 | 2026-09-16 | N/A | 8.8 HIGH | ||
| A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/parameterManage endpoint using user credentials allowing execution of commands with root privileges on the device. | |||||
| CVE-2026-27550 | 2026-09-16 | N/A | 8.8 HIGH | ||
| A low-privileged remote attacker can exploit a command injection vulnerability in the Field_Shadow_Password class using operator credentials allowing execution of commands with root privileges on the device. | |||||
| CVE-2026-27549 | 2026-09-16 | N/A | 8.8 HIGH | ||
| A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/attached_devices_tab/do_upload endpoint using operator credentials allowing execution of commands with root privileges on the device. | |||||
| CVE-2026-27548 | 2026-09-16 | N/A | 8.8 HIGH | ||
| A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/get_iodd_port_info endpoint using user or operator credentials allowing execution of commands with root privileges on the device. | |||||
| CVE-2026-27547 | 2026-09-16 | N/A | 8.8 HIGH | ||
| A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/get_iodd_menu_info endpoint using valid user or operator credentials allowing execution of commands with root privileges on the device. | |||||
| CVE-2026-73447 | 2026-09-16 | N/A | 9.1 CRITICAL | ||
| A privileged attacker can exploit certain operation to execute arbitrary commands with root privileges, leading to full device compromise. An authenticated user can exploit gRPC Network Security Interface (gNSI) Certz service on Arista EOS-based products to escalate privileges and execute arbitrary OS commands via a crafted Certz Rotate request. The Bootz service is also affected. | |||||
| CVE-2026-14277 | 2026-09-16 | N/A | 6.3 MEDIUM | ||
| IBM i Access Family 1.1.2.0 through 1.1.9.15 could allow an authenticated user to execute arbitrary commands with normal user privileges on the system due to improper validation of user supplied input in a session file. | |||||
