Skip to main content

CWE archive

CWE-77 CVEs

Programmatic archive

3,692 CVEs tagged with CWE-77967 Critical, 1,500 High, 777 Medium, 445 Low, 3 Unrated.

CVE-2023-0127

Published Feb 11, 2023

A command injection vulnerability in the firmware_update command, in the device's restricted telnet interface, allows an authenticated attacker to execute arbitrary commands as ro…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-43550

Published Feb 9, 2023

A command injection vulnerability exists in Jitsi before commit 8aa7be58522f4264078d54752aae5483bfd854b2 when launching browsers on Windows which could allow an attacker to insert…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-24157

Published Feb 3, 2023

A command injection vulnerability in the serverIp parameter in the function updateWifiInfo of TOTOLINK T8 V4.1.5cu allows attackers to execute arbitrary commands via a crafted MQT…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-24156

Published Feb 3, 2023

A command injection vulnerability in the ip parameter in the function recvSlaveUpgstatus of TOTOLINK T8 V4.1.5cu allows attackers to execute arbitrary commands via a crafted MQTT…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-24153

Published Feb 3, 2023

A command injection vulnerability in the version parameter in the function recvSlaveCloudCheckStatus of TOTOLINK T8 V4.1.5cu allows attackers to execute arbitrary commands via a c…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-24152

Published Feb 3, 2023

A command injection vulnerability in the serverIp parameter in the function meshSlaveUpdate of TOTOLINK T8 V4.1.5cu allows attackers to execute arbitrary commands via a crafted MQ…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-24151

Published Feb 3, 2023

A command injection vulnerability in the ip parameter in the function recvSlaveCloudCheckStatus of TOTOLINK T8 V4.1.5cu allows attackers to execute arbitrary commands via a crafte…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-24150

Published Feb 3, 2023

A command injection vulnerability in the serverIp parameter in the function meshSlaveDlfw of TOTOLINK T8 V4.1.5cu allows attackers to execute arbitrary commands via a crafted MQTT…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 2,526-2,550 of 3,692 CVEsPage 102 of 148