Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2618+ Articles
162+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
All tags
60 articles

#Command Injection

All CosmicBytez Labs articles tagged #Command Injection, across news, security advisories, how-to guides, and projects.

  • SecurityAug 27, 2026

    CVE-2026-77533: UniFi Protect Command Injection via Improper Input Validation

    A critical flaw in UniFi Protect lets a low-privileged, network-adjacent attacker inject OS commands on the host device. Patch to 7.2.105+.

  • SecurityAug 24, 2026

    CVE-2026-78211: Critical OS Command Injection in 4MOSAn GCB Doctor

    A CVSS 9.8 critical unauthenticated RCE vulnerability in 4MOSAn GCB Doctor exposes systems to full OS command injection via an unremoved ADOdb test page.

  • NewsAug 23, 2026

    NASA AIT-GUI Flaws Could Let Unauthenticated Attackers Issue Spacecraft Commands

    Cycode found chained flaws in NASA's open-source AMMOS Instrument Toolkit GUI allowing unauthenticated attackers to send arbitrary spacecraft commands.

  • SecurityAug 20, 2026

    CVE-2026-53545: Termix SSH Tunnel Command Injection — CVSS 9.8 Critical

    Critical OS command injection in Termix's SSH tunnel teardown lets authenticated attackers execute arbitrary OS commands on hosts. Patch to 2.3.2.

  • SecurityAug 15, 2026

    CVE-2026-50523: Microsoft PowerShell Local Command Injection Vulnerability

    A command injection flaw in Microsoft PowerShell allows authorized local attackers to execute arbitrary code via improper input neutralization.

  • SecurityAug 12, 2026

    SonicWall GMS Unauthenticated Command Injection RCE

    A critical unauthenticated command injection flaw in SonicWall GMS 9.5.1 and earlier allows remote attackers to execute arbitrary code via crafted requests.

  • SecurityAug 10, 2026

    CVE-2026-19348: Critical Command Injection in Shenzhen Aitemi M300 Wi-Fi Repeater

    A CVSS 9.8 critical command injection vulnerability in the Shenzhen Aitemi M300 Wi-Fi Repeater allows unauthenticated remote attackers to execute arbitrary OS commands via the smacfilter configuration endpoint.

  • SecurityAug 9, 2026

    D-Link DWR-M961 Command Injection via FOTA Upgrade Interface (Quectel)

    A command injection vulnerability in D-Link DWR-M961 routers (hardware C1) allows remote attackers to execute arbitrary OS commands via the fota_url parameter in the Quectel FOTA upgrade interface.

  • SecurityAug 9, 2026

    D-Link DWR-M961 Command Injection via FOTA Upgrade Interface (Fibocom)

    A command injection vulnerability in D-Link DWR-M961 routers (hardware C1) allows remote attackers to execute arbitrary OS commands via the fota_url parameter in the Fibocom FOTA upgrade interface.

  • SecurityAug 9, 2026

    D-Link DWR-M961 Command Injection via Ping Diagnostic Interface

    A command injection vulnerability in D-Link DWR-M961 routers (hardware C1) allows remote attackers to execute arbitrary OS commands via the host parameter in the ping diagnostic interface.

  • SecurityAug 9, 2026

    D-Link DWR-M961 Command Injection via Traceroute Diagnostic Interface

    A command injection vulnerability in D-Link DWR-M961 routers (hardware C1) allows remote attackers to execute arbitrary OS commands via the host and ipVer parameters in the traceroute diagnostic interface.

  • SecurityAug 9, 2026

    CVE-2026-71948: D-Link DWR-M961 Command Injection via formDebugDiagnosticRun

    A critical unauthenticated command injection vulnerability in D-Link DWR-M961 routers allows remote attackers to execute arbitrary commands via the host field in the formDebugDiagnosticRun interface. CVSS 9.8.

  • SecurityAug 9, 2026

    CVE-2026-71949: D-Link DWR-M961 Command Injection via formUSSDSetup

    A critical unauthenticated command injection vulnerability in D-Link DWR-M961 routers enables remote code execution through the ussdValue and selectMenuValue fields in the formUSSDSetup interface. CVSS 9.8.

  • SecurityAug 9, 2026

    CVE-2026-71950: D-Link DWR-M961 Command Injection via formSmsManage

    A critical unauthenticated command injection in the D-Link DWR-M961 SMS management interface allows remote attackers to execute arbitrary OS commands via the action_value field. CVSS 9.8.

  • SecurityAug 9, 2026

    CVE-2026-71951: D-Link DWR-M961 Command Injection via formIMEISetup

    A critical unauthenticated command injection vulnerability in D-Link DWR-M961 routers allows remote code execution by injecting OS commands into the IMEI_value field of the formIMEISetup interface. CVSS 9.8.

  • SecurityAug 9, 2026

    MSI Radix AXE6600 Critical Command Injection in WPS Interface (CVE-2026-71983)

    A critical CVSS 9.8 command injection vulnerability in the MSI Radix AXE6600 router's wps.cgi interface allows remote attackers to execute arbitrary commands as root by injecting malicious input through unsanitized WPS PIN parameters.

  • SecurityAug 9, 2026

    MSI Radix AXE6600 Critical Command Injection in URL Filter Function (CVE-2026-71984)

    A critical CVSS 9.8 command injection vulnerability in the MSI Radix AXE6600 router's urlfilter function allows remote attackers to execute arbitrary commands as root, enabling full device takeover via the URL filtering management interface.

  • SecurityAug 9, 2026

    MSI Radix AXE6600 Critical Command Injection in Access Control Function (CVE-2026-71985)

    A critical CVSS 9.8 command injection vulnerability in the MSI Radix AXE6600 router's accesscontrol function enables remote attackers to execute arbitrary commands as root, bypassing network access restrictions and achieving full device compromise.

  • SecurityAug 9, 2026

    MSI Radix AXE6600 Critical Command Injection in DMZ Function (CVE-2026-71986)

    A critical CVSS 9.8 command injection vulnerability in the MSI Radix AXE6600 router's DMZ function allows remote attackers to execute arbitrary commands as root, completing a cluster of four critical command injection flaws in firmware v781521.

  • SecurityAug 8, 2026

    CVE-2026-8037: Progress LoadMaster Command Injection Vulnerability

    Critical unauthenticated command injection in Progress LoadMaster lets attackers run arbitrary OS commands. Listed on the CISA KEV catalog — patch immediately.

  • SecurityAug 5, 2026

    CVE-2026-61515: Puwell IP Camera Unauthenticated Command Injection

    A critical unauthenticated command injection vulnerability in Puwell IP Camera firmware 2.x through 4.x allows remote attackers to execute arbitrary OS commands as root via the device's exposed DebugShell interface on TCP port 34567. No patch is available.

  • SecurityAug 5, 2026

    CVE-2026-66902: Google::Auth Perl Library RCE via Credential JSON Injection

    Google::Auth for Perl versions before 0.06 passes attacker-controlled commands from external_account credentials JSON directly to system(), enabling unauthenticated remote code execution with CVSS 9.8.

  • SecurityAug 4, 2026

    CVE-2026-18602: GL.iNet GL-MT3000 Remote Command Injection via VPN Hostname

    A critical command injection vulnerability in GL.iNet GL-MT3000 routers (firmware up to 4.4.5) allows remote attackers to execute arbitrary OS commands by manipulating the Hostname argument in the OpenVPN client configuration endpoint.

  • SecurityAug 4, 2026

    CVE-2026-6837: Zyxel WAX650S Post-Auth Command Injection (CVSS 7.2)

    A post-authentication command injection vulnerability in the Zyxel WAX650S Wi-Fi 6 access point allows authenticated administrators to execute arbitrary OS commands via the export-cgi CGI program. Firmware versions through 7.10(ABRM.4)C0 are affected.

  • NewsJul 27, 2026

    Arista Patches VeloCloud Orchestrator Zero-Day Exploited in Attacks

    Arista Networks has released an emergency patch for a maximum-severity command injection zero-day in on-premises VeloCloud Orchestrator deployments that is being actively exploited in the wild.

  • SecurityJul 12, 2026

    CVE-2026-61445: PraisonAI AICoder Arbitrary File Write and Command Injection via LLM Tool Calls

    A CVSS 9.9 critical vulnerability in PraisonAI before 4.6.78 allows attackers to write files to arbitrary filesystem locations and execute arbitrary OS...

  • SecurityJul 7, 2026

    CVE-2026-34038: Critical Coolify RCE via Authenticated Command Injection (CVSS 9.9)

    A critical command injection vulnerability in Coolify's deployment pipeline allows any authenticated user with write access to execute arbitrary OS...

  • SecurityJul 7, 2026

    CVE-2026-40047: Apache Camel Docling Argument Injection Enables OS Command Execution

    A critical argument injection vulnerability in Apache Camel's camel-docling component allows attackers to inject arbitrary CLI arguments into the docling...

  • SecurityJul 3, 2026

    UniFi Connect Critical RCE via Command Injection CVE-2026-50746

    A maximum-severity command injection vulnerability in Ubiquiti's UniFi Connect Application allows any network-accessible attacker to execute arbitrary OS...

  • SecurityJul 3, 2026

    UniFi Access Application Command Injection RCE CVE-2026-50748

    An improper input validation flaw in Ubiquiti's UniFi Access Application enables low-privileged network attackers to inject OS commands and execute...

  • SecurityJun 24, 2026

    CVE-2026-12486: GeoVision GV-I/O Box 4E OS Command Injection via libNetSetObj.so

    Multiple OS command injection vulnerabilities in GeoVision GV-I/O Box 4E firmware 2.09 allow attackers with network access to execute arbitrary system...

  • SecurityJun 23, 2026

    CVE-2025-67038: Lantronix EDS5000 OS Command Injection Vulnerability

    A critical OS command injection flaw in the Lantronix EDS5000 serial device server allows unauthenticated attackers to inject arbitrary commands via the...

  • SecurityJun 12, 2026

    CVE-2026-47367: UID Enterprise Agent Command Injection via Improper Input Validation

    A critical CVSS 9.9 command injection vulnerability in UID Enterprise Agent allows a low-privileged network attacker to execute arbitrary commands on the...

  • SecurityJun 12, 2026

    CVE-2026-47370: UniFi OS Command Injection via Improper Input Validation

    A critical CVSS 9.9 command injection vulnerability in Ubiquiti UniFi OS allows a low-privileged network attacker to execute arbitrary commands within...

  • SecurityJun 4, 2026

    CVE-2026-49185: FieldX MDM ADB Topic Command Injection via Runtime.exec()

    A critical CVSS 9.8 command injection vulnerability in the FieldX MDM adb messaging topic passes unverified payloads directly into Runtime.exec(), enabling…

  • SecurityJun 4, 2026

    CVE-2026-49188: ai_cmd Utility Root-Level popen() Injection via Socket Input

    A critical CVSS 9.8 vulnerability in the ai_cmd utility executes with full root permissions and pipes socket inputs directly to popen(), enabling…

  • SecurityMay 22, 2026

    UniFi OS Command Injection via Improper Input Validation

    A CVSS 9.1 command injection vulnerability in UniFi OS devices allows a network-adjacent attacker with high privileges to execute arbitrary commands on...

  • SecurityMay 22, 2026

    CVE-2026-34910 — UniFi OS Unauthenticated Command Injection

    A CVSS 10.0 command injection vulnerability in UniFi OS allows any network-accessible attacker with no credentials to execute arbitrary OS commands,...

  • SecurityMay 22, 2026

    CVE-2026-5433: Honeywell CNM Critical Command Injection RCE

    A CVSS 9.1 critical command injection vulnerability in Honeywell's Control Network Module web interface allows remote attackers to execute arbitrary...

  • SecurityMay 19, 2026

    CVE-2026-25244 — WebdriverIO Command Injection RCE via Git

    A command injection vulnerability in WebdriverIO below version 9.24.0 allows remote code execution through malicious git branch names containing shell...

  • SecurityMay 8, 2026

    CVE-2026-41500: electerm macOS Command Injection via Install Script

    A critical command injection vulnerability in the electerm terminal client allows remote attackers to achieve unauthenticated code execution on macOS...

  • SecurityMay 8, 2026

    CVE-2026-41501: electerm Linux Command Injection via Install Script

    A critical command injection flaw in electerm's Linux installer allows remote attackers to execute arbitrary shell commands by injecting into unsanitized...

  • SecurityApr 30, 2026

    CVE-2026-36841: TOTOLINK N200RE V5 Command Injection

    A critical CVSS 9.8 command injection vulnerability in TOTOLINK N200RE V5 allows unauthenticated remote code execution via the macstr and bandstr...

  • SecurityApr 28, 2026

    CVE-2026-30352: Remote Code Execution in leonvanzyl

    A critical remote code execution vulnerability in the /devserver/start endpoint of the leonvanzyl autocoder AI coding tool allows unauthenticated...

  • SecurityApr 27, 2026

    CVE-2026-7037: Unauthenticated OS Command Injection in Totolink A8000RU

    A critical CVSS 9.8 OS command injection vulnerability in the Totolink A8000RU router allows unauthenticated remote attackers to execute arbitrary...

  • SecurityApr 25, 2026

    CVE-2025-29635: D-Link DIR-823X Command Injection

    A command injection flaw in end-of-life D-Link DIR-823X routers allows authenticated remote attackers to execute arbitrary OS commands. CISA has added...

  • SecurityApr 25, 2026

    CVE-2026-6951: simple-git RCE via --config Option Bypass

    A critical remote code execution vulnerability in the simple-git npm package allows attackers to inject arbitrary git config options via the --config...

  • SecurityApr 24, 2026

    CVE-2026-6942: radare2-mcp OS Command Injection via Shell

    A critical OS command injection vulnerability in radare2-mcp 1.6.0 and earlier allows remote attackers to execute arbitrary commands by bypassing the...

  • SecurityApr 12, 2026

    CVE-2026-6112: Totolink A7100RU OS Command Injection via setRadvdCfg

    A critical OS command injection vulnerability (CVSS 9.8) in Totolink A7100RU firmware allows unauthenticated remote attackers to execute arbitrary...

  • SecurityApr 12, 2026

    CVE-2026-6113: Totolink A7100RU OS Command Injection via setTtyServiceCfg

    A critical OS command injection flaw (CVSS 9.8) in Totolink A7100RU enables remote unauthenticated attackers to execute arbitrary commands by manipulating...

  • SecurityApr 12, 2026

    CVE-2026-6114: Totolink A7100RU OS Command Injection via setNetworkCfg

    CVE-2026-6114 is a critical OS command injection vulnerability (CVSS 9.8) in the Totolink A7100RU router's setNetworkCfg function, exploitable remotely...

  • SecurityApr 12, 2026

    CVE-2026-6115: Totolink A7100RU OS Command Injection via setAppCfg

    CVE-2026-6115 describes a critical OS command injection vulnerability (CVSS 9.8) in the Totolink A7100RU router, exploitable remotely and without...

  • SecurityApr 8, 2026

    CVE-2021-4473: Tianxin Behavior Management System

    A critical unauthenticated command injection vulnerability in the Tianxin Internet Behavior Management System's Reporter component allows attackers to...

  • SecurityApr 1, 2026

    CVE-2026-0596: MLflow Command Injection via Unsanitized

    A critical command injection vulnerability in mlflow/mlflow allows attackers to execute arbitrary shell commands by embedding metacharacters in the...

  • SecurityMar 30, 2026

    CVE-2025-15379: MLflow Command Injection in Model Serving

    A maximum-severity command injection vulnerability in MLflow's model serving container initialization allows attackers to execute arbitrary OS commands...

  • SecurityMar 20, 2026

    CVE-2026-32238: Critical Command Injection in OpenEMR

    OpenEMR versions prior to 8.0.0.2 contain a CVSS 9.1 command injection vulnerability in the backup functionality. Authenticated attackers with high...

  • SecurityMar 17, 2026

    CVE-2025-69902: Critical Command Injection in kubectl-mcp-server

    A critical command injection vulnerability in kubectl-mcp-server allows unauthenticated attackers to execute arbitrary OS commands through unsanitized...

  • SecurityMar 4, 2026

    CISA Adds Actively Exploited VMware Aria Operations RCE

    CISA has added CVE-2026-22719, a high-severity command injection vulnerability in VMware Aria Operations allowing unauthenticated remote code execution,...

  • SecurityFeb 25, 2026

    Soliton FileZen OS Command Injection Under Active

    A high-severity OS command injection vulnerability in Soliton Systems FileZen secure file transfer appliances is being actively exploited. Authenticated...

  • SecurityFeb 15, 2026

    GitHub Copilot Command Injection Flaws Enable Remote Code

    Multiple high-severity command injection vulnerabilities discovered in GitHub Copilot extensions for VS Code, Visual Studio, and JetBrains could allow...